CISA has added CVE-2025-62593, a code injection vulnerability in Ray-Project Ray, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The vulnerability poses significant risks to the federal enterprise and is a frequent attack vector for malicious cyber actors. BOD 26-04 requires FCEB agencies to prioritize rapid remediation of such vulnerabilities on publicly exposed assets that grant total control post-exploitation.
Ray-Project
1 post
CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2025-62593)