CYBERSECURITYTRACKER
TRACKING
Permanent story citation

CISA Adds One Known Exploited Vulnerability to Catalog

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4536

As cited

Copy frozen at (site build).

vulnerabilities

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added CVE-2025-62593, a Ray-Project code injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence. The addition underscores CISA's ongoing effort to track vulnerabilities actively abused by threat actors and reinforces BOD 26-04 requirements for federal agencies to prioritize remediation of high-risk KEV Catalog entries on publicly exposed assets.

Why it matters: All organizations, especially Federal Civilian Executive Branch agencies, should check whether CVE-2025-62593 affects their Ray-Project deployments and patch immediately if exposed to the internet; CISA encourages risk-based prioritization of all KEV Catalog vulnerabilities.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added CVE-2025-62593, a Ray-Project code injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence. The addition underscores CISA's ongoing effort to track vulnerabilities actively abused by threat actors and reinforces BOD 26-04 requirements for federal agencies to prioritize remediation of high-risk KEV Catalog entries on publicly exposed assets.

Why it matters: All organizations, especially Federal Civilian Executive Branch agencies, should check whether CVE-2025-62593 affects their Ray-Project deployments and patch immediately if exposed to the internet; CISA encourages risk-based prioritization of all KEV Catalog vulnerabilities.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary