Ray is on CISA’s KEV catalog. The clock is 20 August.
CISA · OFAC · 6 sources
What's on the official record
17 August — one KEV add. CISA put CVE-2025-62593 (https://www.cve.org/CVERecord?id=CVE-2025-62593) on the Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation. The catalog names Ray-Project Ray. It is a code-injection vulnerability that can allow remote code execution. Date added is 17 August 2026. Due date is 20 August 2026. Weakness classes are CWE-94 (code injection) and CWE-352 (cross-site request forgery). Catalog version is 2026.08.17; the catalog holds 1,666 items.
CISA’s short description is specific: developers using Ray as a development tool may be exposed, and the path is exploitable through Firefox and Safari. Binding Operational Directive 26-04 is the federal civilian clock. It requires FCEB agencies to remediate listed KEV items on publicly exposed assets that grant total control after exploitation, and to check whether the asset was already used before the patch. CISA tells every other operator to treat the catalog the same way.
The vendor advisory CISA points at is GHSA-q279-jhrf-cc6v. Affected pip package ray is every version before 2.52.0; 2.52.0 is the patched release. The advisory describes a jobs-API path (/api/jobs) that can be reached from a developer’s Firefox or Safari session via DNS rebinding, because the product’s browser check on the User-Agent header is not a sufficient control. Chrome is called out as not following that fetch behavior. This note does not restate exploit steps. The advisory is the mitigation source.
The last named official title on OFAC recent-actions remains the 12 August Rice Lake settlement. No newer designation, FAQ, or enforcement title is on that page.
Assessment
For a sanctions committee, 17 August did not add a name, address, or license class. The last official list and enforcement titles remain the 6–12 August window (Cuba technical-import designations; Iran/CT vehicle classes; Rice Lake diversion settlement).
For a country GM/CFO, Ray below 2.52.0 on a workstation or head node that a developer reaches from Firefox or Safari is the estate question. If that path is internet-facing, or reachable from a developer browser that can hit the jobs API, 20 August is the date on the catalog. The Forensics Triage half of BOD 26-04 still applies: check whether the asset was used before the patch.
For a vendor/platform, ask whether Ray sits in a quant, data, or cloud-ML stack you own or buy; whether the version is below 2.52.0; and whether that instance is reachable the way CISA describes. Treating a KEV add as a new SDN name is the wrong class.
What would change this call
| ID | Claim | Resolve by | Hit if | Miss if |
|---|---|---|---|---|
| F1 | CISA does not add a second Ray CVE to KEV before 20 August. | 20 Aug 2026 | Catalog still shows one Ray CVE | A second Ray CVE is added |
| F2 | The 20 August due date is not extended on the CVE-2025-62593 row. | 21 Aug 2026 | dueDate still 2026-08-20 | Catalog posts a later due date |
| F3 | OFAC recent-actions carries no new designation or settlement title through 20 August. | 20 Aug 2026 | Newest dated title still 12 Aug | A newer official title posts |
| F4 | GHSA-q279-jhrf-cc6v remains the vendor mitigation CISA lists on the KEV notes field, and 2.52.0 remains the patched ray release. | 20 Aug 2026 | Same advisory URL and patched version | Notes field or patched version changes |
Base case (stated so it can be wrong): F2 and F3 hold. The due date stands; OFAC stays quiet through 20 August.
What to check next
| Open question | What it takes | Where that comes from |
|---|---|---|
| Is Ray on this estate or in this vendor stack, and is it reachable? | Inventory + network path | Operator file |
| Was a reachable instance used before the patch? | Forensics against the BOD 26-04 Forensics Triage guidance | BOD 26-04 implementation guidance |
| Did a named customer or payment hit last week's OFAC names? | Customer file + current SDN | Operator file; OFAC recent-actions 6–12 August |
Confidence
High on the official-page reading: what CISA published on 17 August, the vendor affected/patched versions in GHSA-q279-jhrf-cc6v, and OFAC remaining quiet on recent-actions. Medium on how widely Ray below 2.52.0 sits in operator estates — that needs a file.
Sources
[1] CISA, CISA Adds One Known Exploited Vulnerability to Catalog, 17 Aug 2026. https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog
[2] CISA, Known Exploited Vulnerabilities Catalog, catalogVersion 2026.08.17, CVE-2025-62593. https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
[3] CISA, Binding Operational Directive 26-04. https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
[4] OFAC, Recent Actions (last named title: Rice Lake settlement, 12 Aug 2026). https://ofac.treasury.gov/recent-actions
[5] Ray Project, GHSA-q279-jhrf-cc6v (CVE-2025-62593); affected ray < 2.52.0, patched 2.52.0. https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v
[6] CISA, Binding Operational Directive 26-04 Implementation Guidance (Forensics Triage Requirements). https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk