Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CISA Urges Swift Action: Actively Exploited Ray RCE Bug Puts Developers at Risk


US federal agencies have been warned to fix a critical Ray Remote Code Execution (RCE) bug within the next three days, as attackers can exploit the vulnerability to gain access to private corporate networks. The bug, tracked as CVE-2025-62593, is rated 9.4 under the Common Vulnerability Scoring System (CVSS) v4 and can be exploited using Firefox or Safari to achieve remote code execution on a vulnerable Ray system.

  • The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to US federal civilian executive branch agencies about a critical Ray Remote Code Execution (RCE) bug.
  • The vulnerability, tracked as CVE-2025-62593, can be exploited using Firefox or Safari to achieve remote code execution on a vulnerable Ray system.
  • Ray is an open-source distributed computing framework used by major tech companies, but its security model has been criticized for its lack of authentication on critical endpoints.
  • Attackers can exploit the bug by visiting a dodgy website or receiving a malicious ad in an affected browser, and can also use DNS rebinding to reach the local Ray service.
  • The Ray 2.52.0 patch fixes the flaw, and CISA has given US federal agencies three days to remediate the vulnerability.
  • The incident highlights the importance of keeping software up-to-date and following best practices for securing open-source dependencies.
  • The Linux Foundation's PyTorch Foundation now manages the Ray project, which has gained significant traction despite its security concerns.



  • The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to US federal civilian executive branch agencies, urging them to fix a critical Ray Remote Code Execution (RCE) bug within the next three days. The vulnerability, tracked as CVE-2025-62593, is rated 9.4 under the Common Vulnerability Scoring System (CVSS) v4 and can be exploited using Firefox or Safari to achieve remote code execution on a vulnerable Ray system.

    Ray is an open-source distributed computing framework used by major tech companies, including Amazon, Apple, and OpenAI. The framework is designed to scale Python and machine-learning workloads from a local environment to a cluster with minimal code changes. Despite its widespread adoption, Ray's security model has been criticized for its lack of authentication on critical endpoints, which has made the bug more vulnerable to exploitation.

    According to CISA, attackers can exploit the bug by visiting a dodgy website or receiving a malicious ad in an affected browser. Once the attacker has gained access, they can use DNS rebinding to reach the local Ray service and execute arbitrary shell code on the developer's machine. The vulnerability can also be used to attack network-adjacent instances of Ray by leveraging the browser as a confused deputy intermediary to attack Ray instances running inside a private corporate network.

    The Ray 2.52.0 patch fixes the flaw, and CISA has given US federal agencies three days to remediate the vulnerability, rather than the standard 14-day window. The agency has not explained the urgency behind the request, but marked the catalog's "known to be used in ransomware campaigns" field as "unknown." The Binding Operational Directive 26-04 allows the agency to impose a three-day remediation window on vulnerabilities it considers especially risky.

    The Ray bug is the latest in a series of security concerns that have plagued the open-source community. In recent months, CISA has warned of phishing and malvertising attacks targeting developers to gain access to private corporate networks. The agency has also issued warnings about self-replicating botnet attacks on Ray clusters and autonomous AI attacks posing a "clear and present danger" to critical infrastructure.

    The incident highlights the importance of keeping software up-to-date and following best practices for securing open-source dependencies. It also underscores the need for developers to be vigilant when using software from the open-source community, especially when it comes to vulnerabilities that can be exploited by attackers.

    The Linux Foundation's PyTorch Foundation now manages the Ray project, which started at UC Berkeley and was commercialized via Anyscale, the startup founded by Ray's developers in 2019. The project has gained significant traction, with over 237 million total downloads and 7 million per week, representing a near-tenfold growth year-on-year.

    Despite its popularity, Ray's security model has been criticized for its lack of authentication on critical endpoints, which has made the bug more vulnerable to exploitation. The project continues to recommend deploying clusters inside a controlled network rather than treating authentication as a substitute for isolation.

    The incident has sparked concerns among security experts and developers, who are urging the open-source community to take immediate action to patch the vulnerability. The CISA warning serves as a reminder of the importance of prioritizing security in software development and the need for developers to stay vigilant when using software from the open-source community.

    In conclusion, the CISA warning about the actively exploited Ray RCE bug highlights the importance of keeping software up-to-date and following best practices for securing open-source dependencies. It also underscores the need for developers to be vigilant when using software from the open-source community, especially when it comes to vulnerabilities that can be exploited by attackers.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CISA-Urges-Swift-Action-Actively-Exploited-Ray-RCE-Bug-Puts-Developers-at-Risk-ehn.shtml

  • https://www.theregister.com/security/2026/08/18/cisa-gives-feds-3-days-to-fix-actively-exploited-ray-rce-bug/5289007

  • https://www.imtr.net/article/cisa-gives-feds-3-days-to-fix-actively-exploited-ray-rce-bug-5025

  • https://nvd.nist.gov/vuln/detail/CVE-2025-62593

  • https://www.cvedetails.com/cve/CVE-2025-62593/


  • Published: Tue Aug 18 13:09:02 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us