CISA Just Put an AI Compute Framework in KEV. A Web Page Is the Exploit.
On August 17, CISA added CVE-2025-62593 to the Known Exploited Vulnerabilities catalog and gave federal civilian agencies three days to fix it. The vulnerable product is Ray, the open-source distributed-compute framework that sits under a large share of modern ML training and inference clusters. The exploit is a browser visit.
That last part is the story. The rest is how it works.
What CVE-2025-62593 is
Ray's dashboard exposes an HTTP API — /api/jobs, /api/job_agent/jobs/ — for submitting and managing jobs on a local Ray instance. The dashboard's only guard against cross-origin abuse is a check that the request's User-Agent header starts with "Mozilla". Per the GitHub advisory, that guard is not a security boundary: the fetch spec lets a page set any User-Agent. Combined with DNS rebinding in the browser, an ordinary web page — or a malvertising banner — can send an HTTP request from the developer's browser to localhost:8265 on their own machine, past same-origin, into the job-submission endpoint. The request runs. The code runs. The developer never noticed.
CVSS 4.0 rates it 9.4, Critical. Ray Project fixed it in version 2.52.0. Every build before that is vulnerable.
The exploitation
Oligo Security is tracking active in-the-wild exploitation as ShadowRay 2.0. Per Oligo via The Hacker News, attackers reach unpatched Ray clusters — many with NVIDIA GPUs attached — and enlist them into self-replicating cryptomining botnets. The attacker economics are good: a Ray cluster is a training substrate, and the GPUs are already there, powered, and paid for.
CISA attached Binding Operational Directive 26-04 and set a federal remediation deadline of August 20 — three days from listing. An unusually short window. It signals CISA believes exploitation is real and moving, and that federal agencies are running Ray at scale.
Why this is the moment AI infrastructure joined the exploitation tier
This is the first time CISA has added an AI compute framework to KEV, per ComplianceHub's analysis of BOD 26-04. Ray sits under a large share of the modern ML stack — Anyscale, Uber, OpenAI, Cohere, and countless internal platforms. Putting a framework at that layer in KEV with a three-day deadline means AI infrastructure is now inside the same exploitation-priority regime as VMware, Ivanti, and Confluence.
And this is the sequel. Oligo's original ShadowRay in March 2024 targeted CVE-2023-48022 against the same Ray dashboard — an authorization surface Anyscale then classified as a "won't fix" configuration issue. Same substrate, same exposed-dashboard-to-RCE shape, same cryptomining payload class, two years later on a new CVE. The Ray dashboard's authorization surface is a repeating architectural failure mode, and CISA is treating it as one.
The boundary the ML team assumed exists
What the exploit does not require: no VPN pivot, no credential theft, no local-network foothold, no dependency compromise. Just a developer running Ray locally — the standard flow — who opens a browser tab. The page can be an ad on a normal site; DNS rebinding does the rest.
Every ML team running Ray on developer laptops has implicitly treated the browser and the compute substrate as different security domains. CVE-2025-62593 names, at CISA-KEV resolution, that they are on the same trust boundary. Because the cluster has the GPUs, training data, and model weights, a full-privilege RCE is one step from weight tampering on whatever job is running.
The pattern
CVE-2025-62593 is not an isolated ML-infra CVE. It is the third disclosure in this digest cycle at the ML-substrate layer to make the same architectural point:
- CVE-2026-43631 — a use-after-free RCE in llama.cpp's
llama-serverwith--sleep-idle-secondsenabled, affecting build range b7492 through b9060. The inference-runtime layer. - The March 2026 LiteLLM PyPI compromise — TeamPCP compromised the Trivy security scanner, chained it into LiteLLM's CI/CD, and pushed backdoored versions to PyPI that touched ~2,488 corporate domains and ~434,000 CI/CD pipeline runs. The AI-gateway layer.
- CVE-2025-62593 — the ShadowRay 2.0 RCE against Ray dashboards. The distributed-compute layer.
Three layers of the same stack, three CVEs or campaigns in short succession, one reading: the substrate under the model is a supply-chain trust boundary the ML team inherits, and the exploitation tempo is now high enough that "patch when it breaks" is no longer a security posture.
If your organization is about to pull down open-weight models — Z.ai's GLM-5.3 open-weights release is scheduled around August 28, per Bloomberg — and run them through a Ray-backed cluster, CVE-2025-62593 is a companion primitive to those weights. The federal deadline is Aug 20. The rest of the ecosystem has no deadline, and exploitation is already in the wild.
SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.