Product1 distinct publisher3 min readUpdated
CVE-2025-62593 is a code-injection flaw in Ray that CISA says is already being exploited, and its own entry says the bug can be reached through a browser. The fix is version 2.52.0.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The US Cybersecurity and Infrastructure Security Agency added a single Ray vulnerability to its Known Exploited Vulnerabilities catalogue on 17 August and set a federal deadline of 20 August to patch or stop running the software, which the publication describes as one of the tightest windows the agency issues [1][2][11]. That is three days [12], and the reason for the compression is that a KEV listing is a statement that the flaw is already being used in real-world attacks [3].
The bug is CVE-2025-62593, a code-injection weakness that can give an attacker remote code execution on a vulnerable Ray deployment without logging in first [4]. CISA does not publish exploitation details [5]. According to CISA's entry, the flaw is unusual in that it can be reached through an ordinary web browser, including Firefox and Safari, rather than requiring direct network access to a Ray service, which lowers the bar for exploitation [6]. Anyscale, which maintains Ray, has fixed the issue in version 2.52.0, so operators on earlier releases are the exposed ones [7][8].
The reason this is an inventory problem rather than a patch problem is what Ray is for. It distributes Python workloads across clusters of CPUs and GPUs [8], which means it rarely sits on one laptop and instead spans pools of expensive compute holding proprietary models, training data, and cloud credentials [9]. The publication's characterisation is that these are systems spun up fast by data-science teams and then quietly forgotten by whoever is meant to be securing them [10]. If that describes your organisation, the first task is not applying 2.52.0. It is finding out how many Ray deployments exist and which are reachable from outside [15].
There is precedent for what exposed Ray attracts. Researchers at Oligo Security documented a campaign they called ShadowRay, tied to a separate and older Ray weakness, in which more than 230,000 internet-exposed servers were scanned, with compromised systems mined for cryptocurrency, credentials, and whole repositories of source code and models [13]. That is a different flaw from the one CISA listed [13], but it establishes that Ray clusters are already a known target class rather than an obscure one.
Two things are worth keeping in proportion. CISA lists the vulnerability's known use in ransomware campaigns as "unknown", so there is no confirmed extortion angle at this stage; the immediate risk is unauthorised code execution and what follows from it [14]. And private-sector operators face no legal clock at all [11]. The federal deadline is enforced through the binding-directive framework that created the catalogue under Binding Operational Directive 22-01 and now runs under the risk-based BOD 26-04 [11]. For everyone else it is a proxy for urgency, not an obligation.
The operational sequence, per the publication, is to locate every Ray deployment, confirm whether it is reachable from outside, restrict access, and move to 2.52.0 without waiting to find out whether you are already on someone's list [15]. Worth noting for context: CISA was itself recently reported to have been caught without its own incident-response playbook [16].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
CISA added a single vulnerability in Ray to its Known Exploited Vulnerabilities catalogue on 17 August.
CISA gave federal agencies until 20 August to patch the software or stop running it, one of the tightest windows it issues.
A KEV listing confirms the flaw is being used in real-world attacks; the point of the listing is not how the attack works but that it is already working.
The bug, tracked as CVE-2025-62593, is a code-injection weakness that can hand an attacker remote code execution on a vulnerable Ray deployment; someone who has never logged in could get a target's machine to run commands of their choosing.
Anyscale has fixed the issue in Ray version 2.52.0, so operators still on earlier releases are the ones exposed.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific and checkable, but single-sourced with no primary documents
The cluster names a CVE identifier, a listing date, a binding federal deadline, the governing directives, the fixing release and a named third-party research campaign — all falsifiable specifics. Against that, one publisher carries the entire story, the CISA entry and any Anyscale advisory are neither quoted nor linked, and the most consequential technical detail (browser reachability) is unverifiable because CISA publishes no exploitation detail. The editorial asides about deployment hygiene and CISA's own missing playbook are asserted without support.
Fix shipped and a regulator acted; real-world exposure and patch uptake unmeasured
There are three concrete real-world events: the KEV addition with a binding federal deadline, the availability of a fixed release (2.52.0), and prior documented mass exploitation of exposed Ray infrastructure via a different flaw. What is absent is any measure of the population affected by this CVE — no exposed-instance count, no version-distribution data, no patch-rate or federal-compliance figure — and the 230,000-server figure belongs to the older ShadowRay weakness, not this one.
Mildly overstated framing over a genuinely urgent, thinly documented core
The underlying event is real and time-critical, and the source is unusually disciplined for the genre: it withholds exploit mechanics, flags CISA's ransomware field as unknown, and explicitly says ShadowRay concerns a different flaw. The overshoot is in framing rather than fabrication — headline and dek language about 'the framework under your ML pipelines', the vivid 230,000-server precedent placed beside an unrelated CVE, and an eye-catching browser-reachability claim that the same article concedes cannot be substantiated because no exploitation detail is published.
Ordinary ad- and newsletter-driven urgency incentive; no disclosed commercial tie
The sole source is a general technology publication that monetises attention and appends a newsletter solicitation, which rewards short-deadline security urgency and 'the framework under your ML pipelines' framing. There is no disclosed relationship with Anyscale, Oligo Security or any vendor, no sponsored placement, and no product being sold in the piece; the security-desk advice is generic hardening rather than a vendor recommendation. The referenced parties do carry their own incentives — Oligo Security benefits from ShadowRay visibility, Anyscale from the story ending at 'upgrade to 2.52.0' — but neither supplied the reporting here.
Moderate: the action is credible, the mechanics are not yet corroborated
Confidence is anchored by the fact that the central assertion is a checkable regulatory action with a named CVE, a named directive framework and a named fix version, all of which are cheap to verify and costly to get wrong. It is capped by single-publisher sourcing, absent primary documents, an unverifiable browser-reachability detail, and no data on affected versions or exposed population. The prudent posture — patch to 2.52.0 and restrict exposure — is robust even if the mechanics are later restated.
security
CVE-2025-62593: A Ray Developer's Browser Is Now the Attack Surface1 distinct publisher
security
CISA's KEV triage guidance tells agencies to collect RAM before they patch1 distinct publisher
security
Thirteen new Metasploit modules close the patch window on SonicWall SMA1000, Ghost CMS and Langflow1 distinct publisher
build
MLflow's webhook tester is now a credential-theft tool, and it is on CISA's KEV list1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026