CISA Orders Feds to Patch Ray RCE Bug in 3 Days
TL;DR. CISA mandated federal agencies fix a critical vulnerability in the Ray AI framework within three days due to active exploitation. - The bug, CVE-2025-62593, allows remote code execution (RCE) on vulnerable Ray systems via specific browser exploits. - Attackers target developers by using phishing or malicious ads to gain access to private corporate networks. - Major tech companies including Amazon, Apple, and OpenAI use the open-source Ray framework.
- CISA issued an emergency directive requiring federal agencies to patch CVE-2025-62593 in the Ray framework.
- The vulnerability (CVSS v4 score 9.4) allows remote code execution through malicious websites or ads targeting developers.
- Ray is an open-source framework for scaling Python and machine-learning workloads, used by major tech firms.
Sources
- CISA gives feds 3 days to fix actively exploited Ray RCE bug — theregister.com