CISA gives feds 3 days to fix actively exploited Ray RCE bug
Phishing, malvertising attacks could target devs to gain access to private corporate networks
The Cybersecurity and Infrastructure Security Agency (CISA) has instructed US federal civilian executive branch agencies to fix a critical vulnerability in Ray, a widely used open-source framework for scaling Python and machine-learning workloads, within three days. Known as CVE-2025-62593, the vulnerability allows attackers to execute arbitrary code on a vulnerable Ray system using Firefox or Safari browsers.
The flaw, tracked since November 2025, is particularly concerning as it can be exploited through phishing attacks or malicious ads to gain unauthorized access to Ray instances in private corporate networks. The issue stems from Ray's default security model, which assumes clusters run inside a trusted, isolated network, leaving authentication and access control to surrounding infrastructure.
Ray 2.52.0, released to address the flaw, introduces optional token-based authentication, though it remains disabled by default. Despite CISA's urgency, the agency did not provide a clear explanation for the three-day window, noting the vulnerability is believed to be used in ransomware campaigns, though the specific field remains unknown.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- CISA gives feds 3 days to fix actively exploited Ray RCE bug theregister.com