CISA Orders Emergency Patch as Ray AI Framework Flaw Faces Active Exploitation

2 Sources

Share

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2025-62593, a critical Ray AI framework vulnerability, to its Known Exploited Vulnerabilities catalog on August 17, 2026. The flaw enables remote code execution through browser-based attacks and is already being exploited in the wild, prompting federal agencies to patch by August 20.

News article

Ray AI Framework Under Active Attack

CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog on August 17, 2026, confirming active exploitation of a critical flaw in the Ray AI framework

1

2

. The open-source AI framework, maintained by Anyscale and used to scale artificial intelligence and machine learning workloads, has more than 43,500 stars on GitHub and powers a significant portion of modern AI training and inference operations

1

. Federal agencies must patch by August 20, 2026, one of the tightest windows CISA issues, signaling the severity of the threat

2

.

Remote Code Execution Through Browser-Based Attacks

CVE-2025-62593 carries a CVSS score of 9.4 and enables remote code execution via web browsers including Mozilla Firefox and Apple Safari through DNS rebinding attacks

1

. The code-injection vulnerability stems from Ray's longstanding lack of authentication on critical endpoints like /api/jobs and /api/job_agent/jobs/, combined with insufficient controls against browser-based attacks where the User-Agent header can be modified

1

. This design choice has repeatedly led to severe security weaknesses. Developers running Ray in development or testing environments who visit malicious websites or are served malicious advertisements can have arbitrary shell code executed on their machines

1

.

Attacks Target AI/ML Infrastructure

The vulnerability's impact extends beyond individual developer machines. Attackers can leverage compromised browsers as confused deputy intermediaries to target Ray instances running inside private corporate networks

1

. Ray clusters typically run across pools of expensive compute holding proprietary models, AI training data, and cloud credentials, making them high-value targets

2

. A BitSight report from March 2026 revealed that RondoDox DDoS botnet operators incorporated the vulnerability into their arsenal two days before public disclosure on November 26, 2025, exploiting an available proof-of-concept

1

.

Pattern of Attacks on Open-Source AI Framework

Unpatched Ray instances have faced sustained attacks beyond CVE-2025-62593. Oligo Security documented the ShadowRay 2.0 campaign targeting infected clusters with NVIDIA GPUs, converting them into self-replicating cryptocurrency mining botnets

1

. Earlier ShadowRay campaigns compromised more than 230,000 internet-exposed servers, with attackers mining for cryptocurrency, credentials, and entire repositories of source code and models

2

. This pattern mirrors broader open-source ecosystem vulnerabilities, recalling the Log4j crisis and raising questions about infrastructure maintained by comparatively small teams becoming single points of failure

2

.

Immediate Action Required

Anyscale fixed the issue in Ray version 2.52.0, with credit to Oligo security researcher Avi Lumelsky for discovering the fetch bypass and Jonathan Leitschuh for the DNS rebinding attack methodology

1

. While CISA lists known ransomware use as "unknown," the immediate risk encompasses unauthorized code execution, data theft, and everything downstream from compromised access

2

. Private sector operators face no legal deadline but should treat the federal August 20 deadline as proxy for urgency. Organizations must locate Ray deployments, confirm external accessibility, restrict access, and upgrade to version 2.52.0 immediately

2

. The Python framework's ubiquity in AI workloads means delayed patching leaves proprietary models and training infrastructure exposed to attackers already exploiting the weakness.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved