Desk note
Ray is on CISA’s KEV catalog. The clock is 20 August.
Enforcement flash · 17 August 2026
CISA added one known-exploited vulnerability today: Ray-Project Ray, code injection, due 20 August. OFAC named no new action.
What's on the official record
17 August — one KEV add. CISA put CVE-2025-62593 on the Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation. The catalog names Ray-Project Ray. It is a code-injection vulnerability that can allow remote code execution. Date added is 17 August 2026. Due date is 20 August 2026. Weakness classes are CWE-94 (code injection) and CWE-352 (cross-site request forgery). Catalog version is 2026.08.17; the catalog holds 1,666 items.[1][2]
CISA’s short description is specific: developers using Ray as a development tool may be exposed, and the path is exploitable through Firefox and Safari. Binding Operational Directive 26-04 is the federal civilian clock. It requires FCEB agencies to remediate listed KEV items on publicly exposed assets that grant total control after exploitation, and to check whether the asset was already used before the patch. CISA tells every other operator to treat the catalog the same way.[1][3][6]
The vendor advisory CISA points at is GHSA-q279-jhrf-cc6v. Affected pip package ray is every version before 2.52.0; 2.52.0 is the patched release. The advisory describes a jobs-API path (/api/jobs) that can be reached from a developer’s Firefox or Safari session via DNS rebinding, because the product’s browser check on the User-Agent header is not a sufficient control. Chrome is called out as not following that fetch behavior. This note does not restate exploit steps. The advisory is the mitigation source.[2][5]
OFAC. The last named official title on recent-actions remains the 12 August Rice Lake settlement. No newer designation, FAQ, or enforcement title is on that page as of this pull.[4]
Assessment
Two different decisions, one day.
For a sanctions, trade-finance, or corridor committee, 17 August did not add a name, address, or license class. The last official list and enforcement titles remain the 6–12 August window (Cuba technical-import designations; Iran/CT vehicle classes; Rice Lake diversion settlement). This KEV item does not change enter / stay / exit, and it does not move a lookback screen by itself.
For a country GM, CFO, or sponsor whose operating book includes data, model, or distributed-compute platforms, the so-what is the estate and the vendor file. Ray is a compute runtime used in those shops. CISA’s own row is about a development-tool path — a workstation or head node that a developer reaches from Firefox or Safari — not a new SDN add. If Ray below 2.52.0 is internet-facing, or reachable from a developer browser on a machine that can hit the jobs API, 20 August is the date on the catalog. The Forensics Triage half of BOD 26-04 still applies: check whether the asset was used before the patch.[6]
For a financial institution, the useful question is vendor and internal-platform inventory, not a new correspondent name. Ask whether Ray sits in a quant, data, or cloud-ML stack you own or buy; whether the version is below 2.52.0; and whether that instance is reachable the way CISA describes. A “no Ray” answer closes this flash. A “yes, unpatched, reachable” answer is a 20 August remediation and a pre-patch compromise check — then a policy question about who is allowed to run unauthenticated jobs APIs on the estate.
Call: treat 20 August as a Ray version-and-reachability clock for anyone who actually runs it. Do not treat a quiet OFAC day as a quiet corridor, and do not treat a KEV add as a new list name.
What would change this call
| ID | Claim | Resolve by | Hit if | Miss if |
|---|---|---|---|---|
| F1 | CISA does not add a second Ray CVE to KEV before 20 August. | 20 Aug 2026 | Catalog still shows one Ray CVE | A second Ray CVE is added |
| F2 | The 20 August due date is not extended on the CVE-2025-62593 row. | 21 Aug 2026 | dueDate still 2026-08-20 | Catalog posts a later due date |
| F3 | OFAC recent-actions carries no new designation or settlement title between this pull and 20 August. | 20 Aug 2026 | Newest dated title still 12 Aug | A newer official title posts |
| F4 | GHSA-q279-jhrf-cc6v remains the vendor mitigation CISA lists on the KEV notes field, and 2.52.0 remains the patched ray release. | 20 Aug 2026 | Same advisory URL and patched version | Notes field or patched version changes |
Base case (stated so it can be wrong): F2 and F3 hold. The due date stands; OFAC stays quiet through 20 August.
What to check next
- Inventory before you escalate. Confirm whether Ray is on the estate or in a named vendor stack, which version, and whether a jobs/dashboard port is reachable from a developer browser or from the internet. If it is absent, this flash is closed for that file.
- If it is there and below 2.52.0, use the vendor advisory. Move to 2.52.0 or apply the mitigation CISA points at. For anything that was reachable, run the pre-patch compromise check the BOD 26-04 Forensics Triage guidance describes — especially on a head node or shared cluster.[6]
- Time the committee. FCEB has a 20 August due date. Everyone else should treat that date as binding if the asset is exposed the way the catalog describes.
- Keep the 6–12 August OFAC names on the lookback list. They did not move today. This item sits alongside that screen.
Three questions stay open on any specific file. Open sources answer none of them.
| Open question | What it takes |
|---|---|
| Is Ray on this estate or in this vendor stack, and is it reachable? | Inventory + network path |
| Was a reachable instance used before the patch? | Forensics against the BOD 26-04 Forensics Triage guidance |
| Did a named customer or payment hit last week's OFAC names? | Customer file + current SDN |
Confidence
High on what CISA published today, on the vendor affected/patched versions in GHSA-q279-jhrf-cc6v, and on OFAC remaining quiet on recent-actions. Medium on how widely Ray below 2.52.0 sits in operator estates — that needs a file.
Sources
[1] CISA, CISA Adds One Known Exploited Vulnerability to Catalog, 17 Aug 2026. https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog↩
[2] CISA, Known Exploited Vulnerabilities Catalog, catalogVersion 2026.08.17, CVE-2025-62593. https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json↩
[3] CISA, Binding Operational Directive 26-04. https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk↩
[4] OFAC, Recent Actions (last named title: Rice Lake settlement, 12 Aug 2026). https://ofac.treasury.gov/recent-actions↩
[5] Ray Project, GHSA-q279-jhrf-cc6v (CVE-2025-62593); affected ray < 2.52.0, patched 2.52.0. https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v↩
[6] CISA, Binding Operational Directive 26-04 Implementation Guidance (Forensics Triage Requirements). https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk↩