CISA orders a threeday patch after a flaw in the Ray AI framework comes under active attack

Image for article CISA orders a threeday patch after a flaw in the Ray AI framework comes under active attack
News Source : The Next Web

News Summary

  • The Cybersecurity and Infrastructure Security Agency has added a vulnerability in Ray to its Known Exploited Vulnerabilities catalogue.
  • The bug, tracked as CVE-2025-62593, is a code-injection weakness that can hand an attacker remote code execution on a vulnerable Ray deployment.
  • Ray is maintained by Anyscale and sits at the heart of modern machine-learning pipelines, distributing workloads across clusters of CPUs and GPUs.
  • It is the kind of system that tends to be spun up fast by data-science teams and then quietly forgotten by whoever is meant to be securing it.

Must read Articles