INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

U.S. CISA Adds Ray-Project Vulnerability to Known Exploited Catalog

| 2026-08-18 08:02 CRITICAL HIGH
Executive Summary AI-generated
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical remote code execution vulnerability in Ray, an AI compute engine, with the CVE-2025-62593 score of 9.4. This flaw allows attackers to exploit browser-based attacks combined with DNS rebinding, potentially leading to arbitrary shell code execution on targeted machines. The vulnerability is insufficiently protected by versions before 2.52.0 and was added to CISA's Known Exploited Vulnerabilities catalog as a Progress LoadMaster vulnerability. Federal agencies are ordered to fix the vulnerability by August 20, 2026, or face significant risk of attacks exploiting this flaw.
Technical Mitigations AI-generated
* Implement authentication on critical endpoints, such as /api/jobs and /api/job_agent/jobs/, to prevent arbitrary code execution. * Monitor HTTP User-Agent headers for modifications that could be used by DNS rebinding attacks. * Regularly update and patch Ray AI Compute Engine to ensure it remains secure against known exploited vulnerabilities like CVE-2025-62593.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShadowRayShadowRay CVE-2025-62593CVE-2025-62593
Target & Sectors
Global Scope defensedefense
Incident Timeline
‎November 2025
Threat actors used a known exploited vulnerability in the Ray system to gain unauthorized access and execute arbitrary code.
organisation the Ray Development
‎November 26, 2025
Threat actors used a proof-of-concept exploit to incorporate the vulnerability into their arsenal two days before it was publicly disclosed.
tactic Ddos
tactic Botnet
organisation BitSight
organisation RondoDox
organisation PoC
‎March 2026
Threat actors used a proof-of-concept exploit to incorporate the vulnerability into their arsenal two days before it was publicly disclosed on November 26, 2025.
tactic Ddos
tactic Botnet
organisation BitSight
organisation RondoDox
organisation PoC
‎Aug 18, 2026
U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog.
‎2026/08/18
U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog due to remote code execution via DNS rebinding attacks, specifically CVE-2025-62593 with a CVSS score of 9.4.
organisation CVE-2025-62593
organisation DNS
organisation Mozilla Firefox
organisation Apple
organisation Ray AI Compute Engine
infrastructure 2.52.0
organisation API
organisation Aviatrix
organisation Oligo
‎August 20, 2026
Threat actors used a known exploit of CVE-2025-62593 to target the Federal Civilian Executive Branch (FCEB) agencies.
vulnerability CVE-2025-62593
attribution FCEB
attribution Federal Civilian Executive Branch
Tactical Metrics
Metrics
infrastructure
‎2.52.0
Software Version
Intelligence Sources