INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
U.S. CISA Adds Ray-Project Vulnerability to Known Exploited Catalog
| 2026-08-18 08:02 CRITICAL HIGHExecutive Summary AI-generated
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical remote code execution vulnerability in Ray, an AI compute engine, with the CVE-2025-62593 score of 9.4. This flaw allows attackers to exploit browser-based attacks combined with DNS rebinding, potentially leading to arbitrary shell code execution on targeted machines. The vulnerability is insufficiently protected by versions before 2.52.0 and was added to CISA's Known Exploited Vulnerabilities catalog as a Progress LoadMaster vulnerability. Federal agencies are ordered to fix the vulnerability by August 20, 2026, or face significant risk of attacks exploiting this flaw.
Technical Mitigations AI-generated
* Implement authentication on critical endpoints, such as /api/jobs and /api/job_agent/jobs/, to prevent arbitrary code execution.
* Monitor HTTP User-Agent headers for modifications that could be used by DNS rebinding attacks.
* Regularly update and patch Ray AI Compute Engine to ensure it remains secure against known exploited vulnerabilities like CVE-2025-62593.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShadowRayShadowRay
CVE-2025-62593CVE-2025-62593
Target & Sectors
Global Scope
defensedefense
Incident Timeline
November 2025
Threat actors used a known exploited vulnerability in the Ray system to gain unauthorized access and execute arbitrary code.
Click on any entity below to view its context and source!
organisation
the Ray Development
"Due to the longstanding decision by the Ray Development team to not implement any sort of authentication on critical endpoints, like the /api/jobs & /api/job_agent/jobs/ has once again led to a severe vulnerability that allows attackers to execute arbitrary code against Ray," according to an advisory shared by Ray maintainers in November 2025.
November 26, 2025
Threat actors used a proof-of-concept exploit to incorporate the vulnerability into their arsenal two days before it was publicly disclosed.
Click on any entity below to view its context and source!
tactic
Ddos
However, a
BitSight report
from March 2026 revealed that the threat actors behind the RondoDox DDoS botnet had incorporated the vulnerability into their arsenal two days before it was publicly disclosed on November 26, 2025, because of the availability of a proof-of-concept (PoC) exploit.
tactic
Botnet
However, a
BitSight report
from March 2026 revealed that the threat actors behind the RondoDox DDoS botnet had incorporated the vulnerability into their arsenal two days before it was publicly disclosed on November 26, 2025, because of the availability of a proof-of-concept (PoC) exploit.
organisation
BitSight
However, a
BitSight report
from March 2026 revealed that the threat actors behind the RondoDox DDoS botnet had incorporated the vulnerability into their arsenal two days before it was publicly disclosed on November 26, 2025, because of the availability of a proof-of-concept (PoC) exploit.
organisation
RondoDox
However, a
BitSight report
from March 2026 revealed that the threat actors behind the RondoDox DDoS botnet had incorporated the vulnerability into their arsenal two days before it was publicly disclosed on November 26, 2025, because of the availability of a proof-of-concept (PoC) exploit.
organisation
PoC
However, a
BitSight report
from March 2026 revealed that the threat actors behind the RondoDox DDoS botnet had incorporated the vulnerability into their arsenal two days before it was publicly disclosed on November 26, 2025, because of the availability of a proof-of-concept (PoC) exploit.
March 2026
Threat actors used a proof-of-concept exploit to incorporate the vulnerability into their arsenal two days before it was publicly disclosed on November 26, 2025.
Click on any entity below to view its context and source!
tactic
Ddos
However, a
BitSight report
from March 2026 revealed that the threat actors behind the RondoDox DDoS botnet had incorporated the vulnerability into their arsenal two days before it was publicly disclosed on November 26, 2025, because of the availability of a proof-of-concept (PoC) exploit.
tactic
Botnet
However, a
BitSight report
from March 2026 revealed that the threat actors behind the RondoDox DDoS botnet had incorporated the vulnerability into their arsenal two days before it was publicly disclosed on November 26, 2025, because of the availability of a proof-of-concept (PoC) exploit.
organisation
BitSight
However, a
BitSight report
from March 2026 revealed that the threat actors behind the RondoDox DDoS botnet had incorporated the vulnerability into their arsenal two days before it was publicly disclosed on November 26, 2025, because of the availability of a proof-of-concept (PoC) exploit.
organisation
RondoDox
However, a
BitSight report
from March 2026 revealed that the threat actors behind the RondoDox DDoS botnet had incorporated the vulnerability into their arsenal two days before it was publicly disclosed on November 26, 2025, because of the availability of a proof-of-concept (PoC) exploit.
organisation
PoC
However, a
BitSight report
from March 2026 revealed that the threat actors behind the RondoDox DDoS botnet had incorporated the vulnerability into their arsenal two days before it was publicly disclosed on November 26, 2025, because of the availability of a proof-of-concept (PoC) exploit.
Aug 18, 2026
U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog.
2026/08/18
U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog due to remote code execution via DNS rebinding attacks, specifically CVE-2025-62593 with a CVSS score of 9.4.
Click on any entity below to view its context and source!
organisation
CVE-2025-62593
CVE-2025-62593 is a critical remote code execution (RCE) vulnerability in Ray, an AI compute engine.
The vulnerability in question relates to
CVE-2025-62593
(CVSS score: 9.4), which can result in remote code execution via web browsers like Mozilla Firefox and Apple Safari by means of a
DNS rebinding attack
.
organisation
DNS
The vulnerability in question relates to
CVE-2025-62593
(CVSS score: 9.4), which can result in remote code execution via web browsers like Mozilla Firefox and Apple Safari by means of a
DNS rebinding attack
.
By combining this weakness with DNS rebinding, an attacker could potentially execute arbitrary code on a developer’s machine simply by getting them to visit a malicious website or view a malicious advertisement while running Ray.
organisation
Mozilla Firefox
The vulnerability in question relates to
CVE-2025-62593
(CVSS score: 9.4), which can result in remote code execution via web browsers like Mozilla Firefox and Apple Safari by means of a
DNS rebinding attack
.
organisation
Apple
The vulnerability in question relates to
CVE-2025-62593
(CVSS score: 9.4), which can result in remote code execution via web browsers like Mozilla Firefox and Apple Safari by means of a
DNS rebinding attack
.
organisation
Ray AI Compute Engine
“Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (
malvertising
).”
“An attacker exploited a code injection vulnerability in Ray AI Compute Engine via a DNS rebinding attack, leading to remote code execution.
infrastructure
2.52.0
Versions before 2.52.0 insufficiently protected the Ray dashboard/API against browser-based attacks.
The issue has been addressed in version 2.52.0 of the Python package.
organisation
API
Versions before 2.52.0 insufficiently protected the Ray dashboard/API against browser-based attacks.
organisation
Aviatrix
reads the
analysis
published by Aviatrix.
organisation
Oligo
Ray has credited Oligo security researcher Avi Lumelsky with discovering the fetch bypass and Jonathan Leitschuh for coming up with the DNS rebinding attack.
August 20, 2026
Threat actors used a known exploit of CVE-2025-62593 to target the Federal Civilian Executive Branch (FCEB) agencies.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-62593
In light of active exploitation of CVE-2025-62593, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply necessary fixes and mitigations by August 20, 2026.
attribution
FCEB
In light of active exploitation of CVE-2025-62593, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply necessary fixes and mitigations by August 20, 2026.
attribution
Federal Civilian Executive Branch
In light of active exploitation of CVE-2025-62593, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply necessary fixes and mitigations by August 20, 2026.
Tactical Metrics
Metrics
infrastructure
2.52.0
Software Version
Click for context!
Versions before 2.52.0 insufficiently protected the Ray dashboard/API against browser-based attacks.
The issue has been addressed in version 2.52.0 of the Python package.
Intelligence Sources
The Hacker News
2026-08-18
Security Affairs
2026-08-18
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-19T07:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
CVE-2025-62593
entity
10x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
6x
timeline
Temporal Reference
August 20, 2026
date
4x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
general metric
Aug
18
aug
Contextual Telemetry
Context Block
9 METRICS
industry
Targeted Sector
Defense
sector
vulnerability
Exploited CVE
CVE-2025-62593
cve
vulnerability
CVSS Score
9
score
infrastructure
Software Version
2.52.0
version
campaign
Campaign
ShadowRay
operation
general metric
Shadowray
2
shadowray
general metric
Score
9
score
general metric
Stars
43,500
stars
general metric
Times
7,900
times
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.