August 18 Security Briefing: Ray CVE-2025-62593 Added to CISA KEV
CISA added Ray code-injection flaw CVE-2025-62593 to its Known Exploited Vulnerabilities catalog. This briefing explains the browser and DNS-rebinding conditions, why local development services can still be exposed, and the priority response.

The key security development
On August 17, 2026, the U.S. Cybersecurity and Infrastructure Security Agency added CVE-2025-62593, a code-injection flaw in Ray, to its Known Exploited Vulnerabilities catalog. The important operational change is not a new disclosure, but confirmation that a previously published flaw has evidence of exploitation.
This briefing covers August 17 at 09:00 through August 18 at 08:59 KST. No newly disclosed or materially changed incident or KISA advisory met the selection threshold in that window. CVE-2026-69414 also remained on hold and did not qualify for a standalone article.
Why local development environments still matter
The official GitHub security advisory lists Ray versions before 2.52.0 as affected. A developer using Firefox or Safari can be exposed when malicious web content and DNS rebinding are combined, allowing the browser to become a path toward a local or network-adjacent Ray service.
A Ray service does not need to be directly exposed to the public internet for the documented browser-assisted path to matter. Review browser use and internal service reachability together.

Priority checks for operators
- Identify Ray installations and versions on developer workstations, analysis servers, and AI or ML clusters using asset and package records.
- For versions earlier than 2.52.0, update to 2.52.0 or later and verify the running version after deployment.
- Restrict the Ray dashboard and job-submission services with host binding, firewalls, security groups, and segmentation.
- If affected developers used Firefox or Safari to view untrusted web content, review Ray job-submission records, unusual processes, and account or token activity.
- Do not treat patching as the only control: disable unnecessary services, reduce reachable network scope, and assess the available authentication feature.
How to set the response priority
Organizations that do not use Ray should record the negative asset finding and continue normal monitoring. Environments running a version before 2.52.0 should prioritize the update even when the service is not directly internet-facing. Where browser activity and Ray development workloads share a device or trust zone, combine patching with exposure reduction and log review.
CISA set August 20, 2026 as the remediation due date for U.S. federal agencies. That deadline is not automatically binding on every organization, but the KEV designation is strong evidence that private-sector operators should not delay patching and reachability controls.
Verification basis
This article reflects official information available through August 18, 2026 at 08:59 KST. Later updates from CISA or the Ray project may change the affected scope or recommended response.
Sources reviewed
- CISA Adds One Known Exploited Vulnerability to CatalogCISA · Official source
- Known Exploited Vulnerabilities CatalogCISA · Official source
- Critical RCE Vulnerability against Ray Devs exploitable via Browser (Safari & Firefox) due to DNS Rebinding AttackRay Project · Official source
SECUFOCUS NOW reorganized and analyzed the material above. This article does not replace the original sources.



Comments
No comments yet.