{"slug": "cisa-gives-agencies-three-days-to-patch-a-critical-flaw-in-ray", "title": "CISA Gives Agencies Three Days to Patch a Critical Flaw in Ray", "summary": "The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-62593, a critical remote code execution flaw in the Ray open-source framework used by OpenAI, Uber, and Amazon, to its Known Exploited Vulnerabilities catalog on August 17, 2026, giving federal agencies until August 20, 2026, to patch or stop using it. The bug, with a CVSS score of 9.4, affects Ray versions before 2.52.0 and is actively exploited via DNS rebinding attacks. Security firm BitSight found the RondoDox DDoS botnet probing for the vulnerability on November 24, 2025, two days before the CVE was published, and CISA's three-day deadline stems from Binding Operational Directive 26-04.", "body_md": "*A critical remote code execution bug in Ray, the open-source framework quietly running under OpenAI, Uber and Amazon's AI systems, is being actively exploited, and CISA just gave federal agencies until today to fix it.*\n\nOn August 17, 2026, the Cybersecurity and Infrastructure Security Agency added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog. The flaw sits in Ray. That's the distributed computing framework OpenAI used to train ChatGPT and GPT models, and that Uber, Shopify, ByteDance and Spotify all rely on to run Python workloads across clusters of machines. Amazon uses it too, to power parts of its recommendation and search systems. CISA's deadline for federal civilian agencies to patch or stop running it: August 20, 2026. Today.\n\nThe bug itself carries a CVSS score of 9.4, just about as severe as these ratings get. According to The Hacker News, it lets an attacker achieve remote code execution against the Ray dashboard through a browser, using Firefox or Safari, via a DNS rebinding attack. You don't need direct network access. You need a victim to load a malicious webpage while their browser sits on the same network as an exposed Ray cluster.\n\nVersions of Ray before 2.52.0 are affected. The fix is simple to state and, for anyone running Ray in production, urgent to execute: upgrade.\n\n## Attackers got there first\n\nSecurity firm BitSight found that the RondoDox DDoS botnet started probing for this exact vulnerability on November 24, 2025. That's two days before CVE-2025-62593 was even formally published. BitSight's researchers concluded the botnet's operators were tracking public vulnerability research directly, rather than waiting around for an official disclosure. That's a meaningfully faster attacker timeline than most defenders plan around.\n\n[CISA Is Using Anthropic's Mythos to Audit Government Code Despite the Ban](https://startupfortune.com/cisa-is-using-anthropics-mythos-to-audit-government-code-despite-the-ban/)\n\nReuters reports CISA's Attack Surface Evaluation team is running Anthropic's Mythos against government code for vulnerabilities, months after the Pentagon blacklisted the company entirely. Meanwhile Alibaba just banned Claude Code in China over alleged tracking code, in the middle of its own distillation fight with Anthropic. - [government agencies using anthropic claude](https://startupfortune.com/cisa-is-using-anthropics-mythos-to-audit-government-code-despite-the-ban/) - [CISA cybersecurity audit tools anthropic](https://startupfortune.com/cisa-is-using-anthropics-mythos-to-audit-government-code-despite-the-ban/)\n\nThere's a strange wrinkle in BitSight's findings, though. RondoDox's observed exploit attempts set their User-Agent string to a value starting with \"Mozilla\", which happens to be the exact prefix Ray's flawed browser check was looking for. In other words, the botnet's own requests may have tripped the guardrail they were trying to get around. Sloppy tradecraft doesn't mean the bug isn't real. CISA changed its assessment of the flaw from proof-of-concept to active exploitation on August 17, which means someone, somewhere, got it working against a live target.\n\nThe three-day patch window isn't arbitrary either. It comes from Binding Operational Directive 26-04, which CISA issued in June 2026 and which the agency has described, according to reporting from Nextgov/FCW, as its most aggressive remediation timeline yet. Instead of a flat deadline based on CVSS score alone, BOD 26-04 scores vulnerabilities against four criteria: asset exposure, KEV catalog status, exploit automation potential and technical impact. Hit all four, and the clock is three days. Ray's flaw did.\n\nBOD 26-04 technically only binds federal civilian agencies, not private companies. But the KEV catalog itself has a track record of shaping private-sector patching priorities anyway, since insurers, auditors and federal contractors all watch it closely. A framework this deeply embedded in AI infrastructure getting flagged this way is the kind of thing security teams outside government tend to notice fast. Deadline or not.\n\n## Nobody sees Ray coming\n\nHere's the part that should worry AI teams more than the CVSS number: Ray is invisible by design. Nobody builds a product called Ray. Data scientists spin up clusters to parallelize training jobs, and the dashboard often ends up exposed to more of the network than anyone intended, sometimes to the open internet. This isn't the first time Ray users got bitten. Security firm Oligo documented a campaign it named ShadowRay back in 2024, where misconfigured, internet-facing Ray dashboards were hijacked to steal compute and data from AI workloads, no CVE required at the time, just an exposed default.\n\nThat history is the real story here. Ray sits underneath a huge share of production AI infrastructure without most people who benefit from it ever typing its name. A framework nobody thinks about is exactly the kind of thing that ends up running unpatched for months. This time, the exploitation showed up before the fix did, and the government's response was to compress the usual grace period down to zero.\n\n**Also read:** [Beijing Opens Its Second World Humanoid Robot Games With 2,056 Machines Competing](https://startupfortune.com/beijing-opens-its-second-world-humanoid-robot-games-with-2056-machines-competing/) • [Apple Rushes Out iOS 26.6.1 to Fix a Zero-Click Image Bug Meta Found First](https://startupfortune.com/apple-rushes-out-ios-2661-to-fix-a-zero-click-image-bug-meta-found-first/) • [OpenAI Launches ChatGPT for Teens but Parents Still Can't See the Chats](https://startupfortune.com/openai-launches-chatgpt-for-teens-but-parents-still-cant-see-the-chats/)", "url": "https://wpnews.pro/news/cisa-gives-agencies-three-days-to-patch-a-critical-flaw-in-ray", "canonical_source": "https://startupfortune.com/cisa-gives-agencies-three-days-to-patch-a-critical-flaw-in-ray/", "published_at": "2026-08-20 07:05:22+00:00", "updated_at": "2026-08-20 07:13:34.046433+00:00", "lang": "en", "topics": ["ai-infrastructure", "ai-safety", "ai-policy"], "entities": ["CISA", "Ray", "OpenAI", "Uber", "Amazon", "BitSight", "RondoDox", "CVE-2025-62593"], "alternates": {"html": "https://wpnews.pro/news/cisa-gives-agencies-three-days-to-patch-a-critical-flaw-in-ray", "markdown": "https://wpnews.pro/news/cisa-gives-agencies-three-days-to-patch-a-critical-flaw-in-ray.md", "text": "https://wpnews.pro/news/cisa-gives-agencies-three-days-to-patch-a-critical-flaw-in-ray.txt", "jsonld": "https://wpnews.pro/news/cisa-gives-agencies-three-days-to-patch-a-critical-flaw-in-ray.jsonld"}}