CISA encourages organizations to prioritize remediation of KEV Catalog vulnerabilities. Specific patch instructions are not provided in the advisory; organizations should consult Ray-Project official guidance for patching and mitigation steps. Federal agencies must follow Binding Operational Directive 26-04 requirements for rapid remediation on publicly exposed assets.
Quick answers
What is CVE-2025-62593?
CISA encourages organizations to prioritize remediation of KEV Catalog vulnerabilities. Specific patch instructions are not provided in the advisory; organizations should consult Ray-Project official guidance for patching and mitigation steps. Federal agencies must follow Binding Operational Directive 26-04 requirements for rapid remediation on publicly exposed assets.
How severe is CVE-2025-62593?
high
Is CVE-2025-62593 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2025-62593 be mitigated?
CISA encourages organizations to prioritize remediation of KEV Catalog vulnerabilities. Specific patch instructions are not provided in the advisory; organizations should consult Ray-Project official guidance for patching and mitigation steps. Federal agencies must follow Binding Operational Directive 26-04 requirements for rapid remediation on publicly exposed assets.
CVSS
—
Vendor
Ray-Project
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
Ray-Project Ray
Mitigation
CISA encourages organizations to prioritize remediation of KEV Catalog vulnerabilities. Specific patch instructions are not provided in the advisory; organizations should consult Ray-Project official guidance for patching and mitigation steps. Federal agencies must follow Binding Operational Directive 26-04 requirements for rapid remediation on publicly exposed assets.
On August 17, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-62593, a code injection vulnerability in Ray-Project Ray, to its Known Exploited Vulnerabilities (KEV) Catalog. The addition is based on evidence of active exploitation. CISA's Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of this vulnerability on publicly exposed assets that grant total control post-exploitation.