Government Advisory

CISA Flags Actively Exploited Flaw in Ray-Project AI Framework

CISA · 17 Aug 2026
Key Takeaway If your business uses the Ray AI framework, check your version against CVE-2025-62593 and apply patches immediately, as this flaw is being actively exploited in the wild.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-62593, a code injection vulnerability affecting Ray-Project's Ray platform, to its Known Exploited Vulnerabilities (KEV) Catalog. This listing means CISA has confirmed the flaw is being actively used by attackers, making it a priority for organisations using the affected software to patch or mitigate immediately.

CISA's new Binding Operational Directive (BOD 26-04) requires US federal agencies to prioritise fixing high-risk vulnerabilities like this one on any publicly exposed systems, especially where exploitation could give attackers full control. While this directive is mandatory only for federal agencies, CISA is encouraging all organisations, including small and medium businesses, to adopt the same risk-based approach to vulnerability management.

Ray is a popular open-source framework used for building and scaling AI and machine learning applications. Businesses using Ray in their development or production environments should check whether they are running an affected version and apply any available patches or vendor guidance without delay.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.