The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog, imposing a three-day deadline — until August 20 — for federal civilian agencies to patch a critical remote-code-execution vulnerability in Ray, the distributed AI framework widely used across the tech industry.

Ray is deployed by Amazon, Apple, and OpenAI to scale machine learning workloads across distributed GPU clusters. The vulnerability, rated CVSS 9.4, allows an attacker to achieve arbitrary code execution on any local Ray instance running a version below 2.52.0 through a DNS rebinding attack that chains a malicious website with Firefox or Safari browser access.

The flaw was first disclosed in November 2025 and patched in Ray version 2.52.0, but the aggressive federal deadline signals government concern about active exploitation. Security firm Oligo has reported that the ShadowRay 2.0 campaign is already converting compromised NVIDIA-GPU clusters running Ray into self-replicating cryptomining botnets.

The vulnerability illustrates the growing attack surface of AI infrastructure. As organizations deploy frameworks like Ray to manage distributed training and inference, the security of these foundational layers becomes critical. A compromised Ray instance can give attackers access to powerful GPU clusters, training data, and the ability to pivot deeper into corporate networks.

CISA's action reflects a broader push to secure AI systems against both nation-state actors and cybercriminals, with AI frameworks increasingly targeted as high-value assets in the cybersecurity landscape.