CISA orders federal agencies to patch critical Ray RCE flaw within three days
The Cybersecurity and Infrastructure Security Agency gave U.S. civilian agencies three days to remediate a high-severity remote code execution bug in the open-source Ray framework.
CISA announced an accelerated remediation deadline for a critical remote code execution vulnerability in Ray, an open-source platform used for scaling Python and machine-learning workloads. The bug, catalogued as CVE-2025-62593 with a CVSS v4 rating of 9.4, enables exploitation via Firefox or Safari by manipulating the User-Agent header, allowing attackers to reach local Ray services through DNS rebinding. Developers could be compromised simply by loading a malicious webpage or advertisement, with the risk extending to adjacent corporate systems.
Ray 2.52.0 introduces optional token-based authentication, though it remains off by default. Leveraging Binding Operational Directive 26-04, CISA reduced the standard fourteen-day patch period to three days for federal civilian executive-branch entities.
Why it matters
A widely used AI framework harbors a severe flaw that could let hackers infiltrate government and corporate networks if not patched quickly.
In this story
