Our takeCISA added this browser-triggerable RCE in Ray to its KEV catalog, which means active exploitation is confirmed, not alleged. If you run Ray for ML workloads, patch now; if you don't, this one doesn't touch you.Cyber Resilience desk
Sources (1)
- register_sec · register_sec
What this means for you — Security leader:CISA added this Ray RCE (CVE-2025-62593) to the KEV catalog, confirming active exploitation. Federal agencies must patch within 3 days; all other enterprises running Ray for ML workloads should apply the vendor update immediately.
What this means for you — Lean IT orgs:If you run Ray for machine learning, update it right away. Most small teams do not use Ray and can ignore this one.
What this means for you — MSP:Check every client that runs Ray (especially ML or analytics stacks) and confirm the patch is applied. Federal clients have a 3-day binding deadline under CISA policy.
What this means for you — Researcher:CISA has listed CVE-2025-62593 in Ray with confirmed in-the-wild exploitation. The Register notes possible phishing or malvertising vectors aimed at developers.