Our takeCISA added this browser-triggerable RCE in Ray to its KEV catalog, which means active exploitation is confirmed, not alleged. If you run Ray for ML workloads, patch now; if you don't, this one doesn't touch you.Cyber Resilience desk
Sources (1)
- hackernews · hackernews
What this means for you — Security leader:CISA added CVE-2025-62593 (code injection in Ray) to the KEV catalog after confirming active exploitation. Patch it today if you run Ray.
What this means for you — Lean IT orgs:CISA confirmed active exploitation of a code-injection flaw in Ray. If you run Ray yourself, update it in your next maintenance window; most teams that don't use it can ignore this.
What this means for you — MSP:CISA added an actively exploited code-injection flaw in Ray (CVE-2025-62593) to its KEV catalog. Check client environments that run Ray or depend on services that do and patch immediately.
What this means for you — Researcher:CISA added CVE-2025-62593 in Ray to the KEV catalog citing active exploitation. No technical mechanism has been disclosed.