U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog
Overview
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Ray, a data framework, to its Known Exploited Vulnerabilities catalog. This vulnerability, tracked as CVE-2025-62593, has a high severity score of 9.4 and allows for remote code execution, meaning attackers could potentially take control of affected systems without physical access. Organizations using Ray need to be aware of this vulnerability as it poses significant risks to their data and infrastructure. CISA's inclusion of this flaw in their catalog indicates that it is being actively exploited in the wild, prompting an urgent need for users to address the issue. The agency's action serves as a reminder for companies to regularly update their systems and monitor for vulnerabilities to protect against potential attacks.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Ray (data framework), Progress LoadMaster
- Action Required: Organizations should apply the latest security patches for Ray as soon as they become available.
- Timeline: Newly disclosed
Original Article Summary
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Ray-Project Ray vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2025-62593 (CVSS score of 9.4), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2025-62593 is a critical remote code execution (RCE) vulnerability in Ray, […]
Impact
Ray (data framework), Progress LoadMaster
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Organizations should apply the latest security patches for Ray as soon as they become available. Additionally, users are advised to review their configurations and limit access to the affected systems to mitigate potential exploitation until patches are implemented.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Update, and 2 more.