Skip to content

Product1 publisher3 min readPublished

CISA gives federal agencies three days to patch Ray, the framework under your ML pipelines

CVE-2025-62593 is a code-injection flaw in Ray that CISA says is already being exploited, and its own entry says the bug can be reached through a browser. The fix is version 2.52.0.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying CISA gives federal agencies three days to patch Ray, the framework under your ML pipelines
Photo: thenextweb.com

What happened

  • CISA added a single vulnerability in Ray to its Known Exploited Vulnerabilities catalogue on 17 August.
  • CISA gave federal agencies until 20 August to patch the software or stop running it, one of the tightest windows it issues.
  • A KEV listing confirms the flaw is being used in real-world attacks; the point of the listing is not how the attack works but that it is already working.
  • The bug, tracked as CVE-2025-62593, is a code-injection weakness that can hand an attacker remote code execution on a vulnerable Ray deployment; someone who has never logged in could get a target's machine to run commands of their choosing.
  • CISA does not publish exploitation details.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

The US Cybersecurity and Infrastructure Security Agency added a single Ray vulnerability to its Known Exploited Vulnerabilities catalogue on 17 August and set a federal deadline of 20 August to patch or stop running the software, which the publication describes as one of the tightest windows the agency issues [1][2][11]. That is three days [12], and the reason for the compression is that a KEV listing is a statement that the flaw is already being used in real-world attacks [3].

The bug is CVE-2025-62593, a code-injection weakness that can give an attacker remote code execution on a vulnerable Ray deployment without logging in first [4]. CISA does not publish exploitation details [5]. According to CISA's entry, the flaw is unusual in that it can be reached through an ordinary web browser, including Firefox and Safari, rather than requiring direct network access to a Ray service, which lowers the bar for exploitation [6]. Anyscale, which maintains Ray, has fixed the issue in version 2.52.0, so operators on earlier releases are the exposed ones [7][8].

The reason this is an inventory problem rather than a patch problem is what Ray is for. It distributes Python workloads across clusters of CPUs and GPUs [8], which means it rarely sits on one laptop and instead spans pools of expensive compute holding proprietary models, training data, and cloud credentials [9]. The publication's characterisation is that these are systems spun up fast by data-science teams and then quietly forgotten by whoever is meant to be securing them [10]. If that describes your organisation, the first task is not applying 2.52.0. It is finding out how many Ray deployments exist and which are reachable from outside [15].

There is precedent for what exposed Ray attracts. Researchers at Oligo Security documented a campaign they called ShadowRay, tied to a separate and older Ray weakness, in which more than 230,000 internet-exposed servers were scanned, with compromised systems mined for cryptocurrency, credentials, and whole repositories of source code and models [13]. That is a different flaw from the one CISA listed [13], but it establishes that Ray clusters are already a known target class rather than an obscure one.

Two things are worth keeping in proportion. CISA lists the vulnerability's known use in ransomware campaigns as "unknown", so there is no confirmed extortion angle at this stage; the immediate risk is unauthorised code execution and what follows from it [14]. And private-sector operators face no legal clock at all [11]. The federal deadline is enforced through the binding-directive framework that created the catalogue under Binding Operational Directive 22-01 and now runs under the risk-based BOD 26-04 [11]. For everyone else it is a proxy for urgency, not an obligation.

The operational sequence, per the publication, is to locate every Ray deployment, confirm whether it is reachable from outside, restrict access, and move to 2.52.0 without waiting to find out whether you are already on someone's list [15]. Worth noting for context: CISA was itself recently reported to have been caught without its own incident-response playbook [16].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories