← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 18, 2026 · 08:02via Security Affairs

U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog

Brief

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Ray-Project Ray vulnerability to its Known Exploited Vulnerabilities catalog.

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2025-62593 (CVSS score of 9. 4), to its Known Exploited Vulnerabilities (KEV) catalog .

CVE-2025-62593 is a critical remote code execution (RCE) vulnerability in Ray, an AI compute engine. Versions before 2.

  • 0 insufficiently protected the Ray dashboard/API against browser-based attacks. Its defense relied on checking whether the HTTP User-Agent header started with “Mozilla”, but browsers can modify this header.
Read more on Security Affairs