Skip to content

164news.com

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of Service
  • Cookie Policy

CISA orders a three-day patch after a flaw in the Ray AI framework comes under active attack

Posted on August 18, 2026 By Emily Chen No Comments on CISA orders a three-day patch after a flaw in the Ray AI framework comes under active attack

CISA Issues Urgent Patch for Ray AI Framework Flaw

A code-injection bug in Ray, the open-source engine powering countless AI workloads, is actively being exploited in the wild. US federal agencies have until August 20th to patch it, and private operators are advised not to wait.

August 18, 2026 – 10:11 am
Credit: CISA

America’s cyber-defence agency, the Cybersecurity and Infrastructure Security Agency (CISA), has added a critical vulnerability in Ray—the open-source framework behind a significant portion of global AI training and inference—to its Known Exploited Vulnerabilities (KEV) catalogue. This confirms that the flaw is being actively exploited.

On August 17th, CISA issued an alert, giving federal agencies just three days to patch the software or discontinue its use.

The bug, tracked as CVE-2025-62593, is a code-injection weakness that grants attackers remote code execution privileges on vulnerable Ray deployments. In simple terms, this allows an attacker who has never logged in to execute commands on a target machine.

CISA does not disclose exploit details, and neither will we; the purpose of listing a KEV is not to explain how an attack works but to confirm that it is working.

This vulnerability is significant due to Ray‘s widespread use in modern machine learning pipelines, distributing Python workloads across clusters of CPUs and GPUs. Its ubiquity means operators often forget to secure these systems properly. Anyscale, the framework’s maintainer, has fixed the issue in Ray version 2.52.0; older versions remain vulnerable.

According to CISA, this flaw is unique as it can be exploited through an ordinary web browser, including Firefox and Safari, without requiring direct network access to a Ray service. This lowers the barrier for exploitation significantly.

Ray‘s vulnerability highlights broader concerns within the open-source community. Widely deployed infrastructure maintained by small teams becomes a single point of failure for everyone relying on it—a reality underscored by the Log4j crisis and subsequent funding questions regarding open-source projects. AI’s increased use of such compute raises the stakes even higher, as valuable network resources are now at play.

Ray clusters have been targeted before; Oligo Security researchers documented a campaign called ShadowRay, linked to an older Ray weakness, which compromised over 230,000 publicly exposed servers for cryptocurrency mining, credential theft, and even stealing source code and models.

While CISA doesn’t currently link the latest flaw to ransomware campaigns, it does mention "unknown" use cases, suggesting a potential risk of unauthorised code execution and its consequent consequences.

Clock

Post navigation

Previous Post: An analysis links violent AI ‘slop’ to ‘brain rot’ and violence in children
Next Post: Beyond Venture Capital: Why family offices are becoming AI’s most influential investors

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Editor's Picks

  • NYC Construction Law Specialist
  • NY Criminal Defense Lawyer
  • Manhattan Family Law Specialist
  • Queens Immigration Lawyer
  • Staten Island Civil Rights Advocate
  • Manhattan Personal Injury Prevention
  • Bronx Intellectual Property Attorney
  • Long Island Real Estate Dispute Resolution
  • Commercial Plumbing Installation Denver
  • Denver Plumber for Emergency Services

Recent Posts

  • Beyond Venture Capital: Why family offices are becoming AI’s most influential investors
  • CISA orders a three-day patch after a flaw in the Ray AI framework comes under active attack
  • An analysis links violent AI ‘slop’ to ‘brain rot’ and violence in children
  • Florida Primary Underscores State’s New Identity as a Republican Juggernaut
  • Tesla’s Cybercab is finally launching, and it starts by giving its own staff a lift

Recent Comments

  1. tamubetlogin on AMD raises $4.75bn in its biggest ever bond sale
  2. m711casino on The Gadget That Fixed My Screen-Time Habit
  3. betmexicobono on Max Miller, Accused of Abuse, Is Not Stepping Aside. Here’s What We Know.
  4. idjayaslot on China’s new AI bottleneck isn’t chips. It’s running out of Chinese-language training data.
  5. 7f777game on They Were Voted Out. They Refuse to Leave. Now What?

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026

Editor's Picks

  • NYC Construction Law Specialist
  • NY Criminal Defense Lawyer
  • Manhattan Family Law Specialist
  • Queens Immigration Lawyer
  • Staten Island Civil Rights Advocate
  • Manhattan Personal Injury Prevention
  • Bronx Intellectual Property Attorney
  • Long Island Real Estate Dispute Resolution
  • Commercial Plumbing Installation Denver
  • Denver Plumber for Emergency Services

Copyright © 2026 164news.com.

Powered by PressBook Dark WordPress theme