News

CISA orders a three-day patch after a Ray AI flaw comes under active attack

CISA added CVE-2025-62593, a remote-code-execution flaw in the Ray AI framework, to its Known Exploited Vulnerabilities catalog and gave federal agencies until August 20 to patch. The bug hits Ray versions before 2.52.0 through the dashboard and API.

CISA orders a three-day patch after a Ray AI flaw comes under active attack

The US cyber-defence agency CISA has added a single flaw in Ray, the open-source framework behind a large share of the world's AI training and inference, to its Known Exploited Vulnerabilities catalog, confirming the bug is being used in real attacks. As The Next Web reported, the agency made the move on August 17 and gave federal agencies until August 20 to patch or stop running the software, one of the tightest windows it issues.

CISA

The bug is tracked as CVE-2025-62593, a code-injection weakness in Ray. Per Security Affairs, versions before 2.52.0 do not adequately protect the Ray dashboard and API against browser-based attacks, which opens the door to remote code execution on the machine running Ray. The Hacker News framed the danger the same way: a request that reaches an exposed Ray endpoint can end with an attacker running commands.

Ray is the distributed-computing engine that many teams use to scale machine learning, data processing, and plain Python workloads. Those dashboards often sit on internal networks or get exposed to the internet during development. Cybersecurity News notes the risk is highest for developers running vulnerable Ray dev environments. A browser-reachable endpoint that yields code execution is the kind of soft target that gets swept up in mass scanning, which is likely why CISA moved this to active-exploitation status.

The fix is Ray 2.52.0 or later. The three-day federal deadline is a fair signal of urgency beyond government networks. Binding the dashboard to localhost, putting it behind authentication, and keeping the Ray API off the internet are the exposure controls that sit alongside the upgrade.

The same tooling teams rush to stand up for model training can hand an attacker a shell if it is left open, and the risk grows as more code and internal systems get wired into these frameworks, the same exposure worth watching alongside prompt injection.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free