CISA Flags Actively Exploited Ray Vulnerability Affecting Amazon, Apple, OpenAI Infrastructure

Author

AI News Editorial

Published

2026-08-22 08:45

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in the Ray distributed computing framework to its Known Exploited Vulnerabilities (KEV) catalog, marking it as actively exploited in the wild. The vulnerability, tracked as CVE-2025-62593, affects Ray versions prior to 2.52.0 and carries a CVSS 4.0 score of 9.4, indicating severe risk.

Ray is an open-source distributed computing framework widely used for scaling machine learning workloads. The framework serves as infrastructure for major technology companies including Amazon, Apple, and OpenAI, making this vulnerability particularly significant for the AI industry. Organizations use Ray to orchestrate training and inference across clusters of GPUs, making the framework a critical component of AI infrastructure.

The vulnerability allows remote code execution on systems running vulnerable Ray development environments. Attackers can exploit the flaw through DNS rebinding techniques, enabling browser-based remote code execution on developer systems. This means attackers could potentially compromise developer machines that have Ray instances exposed, potentially gaining access to sensitive AI training data and model weights.

CISA issued a binding operational directive requiring federal civilian executive branch (FCEB) agencies to remediate the vulnerability within three days of addition to the KEV catalog. The aggressive timeline reflects the severity of the threat and the likelihood of active exploitation. While the directive applies only to FCEB agencies, CISA strongly encourages all organizations using Ray to prioritize remediation.

The addition to the KEV catalog on August 17, 2026 changed the vulnerability’s assessment from proof-of-concept availability to confirmed active exploitation. Security researchers had previously documented the vulnerability’s technical details, but the shift to active exploitation triggered CISA’s emergency response protocols.

For organizations running Ray clusters, the immediate recommended action is upgrade to Ray version 2.52.0 or later. Organizations unable to patch should immediately review access controls, ensure Ray dashboards are not internet-facing, and implement network segmentation to limit potential blast radius. Given Ray’s use in AI training environments, a successful exploit could expose valuable intellectual property including training data, model weights, and proprietary algorithms.

This vulnerability highlights the expanding attack surface of AI infrastructure. As organizations deploy more distributed computing frameworks for AI workloads, security teams must extend vulnerability management practices to include these specialized tools. The incident also underscores the importance of maintaining current patches on development environments, not just production systems.