CISA Adds One Known Exploited Vulnerability to Catalog

Summary

CISA has added a new vulnerability, CVE-2025-62593 (Ray-Project Ray Code Injection Vulnerability), to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This addition is part of CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize the remediation of high-risk vulnerabilities listed in the KEV Catalog.

IFF Assessment

FOE

The addition of a new, actively exploited vulnerability to CISA's KEV catalog represents bad news for defenders as it highlights a known risk that attackers are currently leveraging.

Severity

8.8 High

CISA KEV: Listed as actively exploited. Federal patch due: August 21, 2026. Known ransomware use: Unknown.

Defender Context

The addition of CVE-2025-62593 to CISA's KEV catalog signifies that this vulnerability is actively being exploited, making it a priority for defenders. Organizations, particularly federal agencies, must prioritize patching or mitigating this vulnerability to prevent successful attacks, as outlined by BOD 26-04.

Read Full Story →