CRITICAL: Ray CVE-2025-62593 Added to CISA KEV After Active Exploitation
CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog on August 17, 2026, giving federal civilian agencies until August 20 to remediate. The critical 9.4 flaw in the Ray distributed AI framework lets a malicious web page reach an otherwise unexposed Ray dashboard through DNS rebinding and execute arbitrary code. The RondoDox botnet weaponized it two days before public disclosure, and every version before Ray 2.52.0 is affected.