THREAT INTELLIGENCE CYBERTTAKv3.0.3.0
LIVE FEED ACTIVE
← Back to Intel Feed
Secure route: /intel/ai-cisa-adds-ray-project-ray-code-injection-vulnerability-to-kev-catalog-8ec714dd
criticalCVE-2025-625932026-08-17Vector: appsec

CISA Adds Ray-Project Ray Code Injection Vulnerability to KEV Catalog

CISA has officially added a code injection vulnerability found in Ray-Project Ray to its Known Exploited Vulnerabilities catalog. This move requires federal agencies to prioritize patching this security flaw due to evidence of active exploitation in the wild.

Decision Context

English Brief

CISA has officially added a code injection vulnerability found in Ray-Project Ray to its Known Exploited Vulnerabilities catalog. This move requires federal agencies to prioritize patching this security flaw due to evidence of active exploitation in the wild.

الموجز العربي

وكالة الأمن السيبراني الأمريكية تضيف ثغرة حقن كود في Ray-Project إلى قائمة الاستغلال المعروفة

أضافت وكالة الأمن السيبراني الأمريكية ثغرة تتعلق بحقن الأكواد البرمجية في مشروع Ray-Project إلى قائمة الثغرات المستغلة فعلياً. يفرض هذا الإجراء على الجهات الفيدرالية إعطاء الأولوية لتصحيح هذه الثغرة نظراً لوجود أدلة على استغلالها من قبل المهاجمين.

Affected Products
    Priority sectors
    Federal GovernmentResearch and DevelopmentTechnology
    Immediate Actions
    1. 1Identify all instances of Ray running in your environment.
    2. 2Check current version: ray --version
    3. 3Update Ray to the latest secure version using pip or your package manager:
    CISA Adds Ray-Project Ray Code Injection Vulnerability to KEV Catalog | Cyberttak