# Critical Ray AI Framework Vulnerability Exploited in Wild

> A critical vulnerability in Ray, the open-source framework used to scale machine learning workloads at companies like OpenAI, Apple, and Amazon, is being actively exploited in the wild. Tracked as CVE-2025-62593 and rated a severe 9.4, the flaw allows code injection through a DNS rebinding attack, stemming from insufficient protections on Ray's HTTP API endpoints. The urgency is real. CISA added the bug to its known-exploited catalog and gave federal agencies just three days to patch, with a deadline of August 20. A fix landed in Ray version 2.52.0, so the remedy exists, but the tight window underscores that attackers are already using it. The story is a useful counterweight to the usual AI headlines about capabilities and funding. As machine learning infrastructure spreads into critical systems, the plumbing that runs these models becomes a high-value target, and a single flaw in a widely used framework can expose some of the biggest names in tech at once. Security is quietly becoming one of the most important AI stories of the year.

_Section: [Daily AI Updates](https://www.wortins.com/daily-ai) · Source: The Next Web · Published Friday, August 21, 2026_

## Wortins' read

A critical vulnerability in Ray, the open-source framework used to scale machine learning workloads at companies like OpenAI, Apple, and Amazon, is being actively exploited in the wild. Tracked as CVE-2025-62593 and rated a severe 9.4, the flaw allows code injection through a DNS rebinding attack, stemming from insufficient protections on Ray's HTTP API endpoints. The urgency is real. CISA added the bug to its known-exploited catalog and gave federal agencies just three days to patch, with a deadline of August 20. A fix landed in Ray version 2.52.0, so the remedy exists, but the tight window underscores that attackers are already using it. The story is a useful counterweight to the usual AI headlines about capabilities and funding. As machine learning infrastructure spreads into critical systems, the plumbing that runs these models becomes a high-value target, and a single flaw in a widely used framework can expose some of the biggest names in tech at once. Security is quietly becoming one of the most important AI stories of the year.

## Source

[Read the full story at The Next Web](https://thenextweb.com/news/cisa-kev-ray-ai-framework)

## Related coverage

- [Callosum Raises $100 Million to Match AI Tasks with Most Cost-Effective Models](https://www.wortins.com/story/callosum-raises-100-million-to-match-ai-tasks-with-most-cost-da05cef6) — [Bloomberg](https://www.bloomberg.com/news/articles/2026-08-20/ai-startup-callosum-raises-100-million-to-make-ai-tasks-cheaper)
- [Nvidia Agrees to Acquire Hugging Face for $13 Billion](https://www.wortins.com/story/nvidia-agrees-to-acquire-hugging-face-for-13-billion-17f12bb8) — [TechCrunch](https://techcrunch.com/2026/08/26/nvidia-closes-in-on-hugging-face-acquisition/)
- [Cohere Launches Command A+ Mixture-of-Experts Model](https://www.wortins.com/story/cohere-launches-command-a-mixture-of-experts-model-5d840970) — [Cohere](https://docs.cohere.com/docs/command-a-plus)
- [Anthropic Adds Claude Mythos 5 to Claude Security for Vulnerability Scanning](https://www.wortins.com/story/anthropic-adds-claude-mythos-5-to-claude-security-for-vulner-34ff7302) — [Anthropic](https://claude.com/blog/bringing-claude-mythos-5-to-more-defenders)
- [Chinese AI Models Now 60% of OpenRouter Traffic, Surpassing US Market Share](https://www.wortins.com/story/chinese-ai-models-now-60-of-openrouter-traffic-surpassing-us-ff49998d) — [Fortune](https://fortune.com/2026/08/21/what-is-ai-death-zone-china-models-open-source/)
- [DARPA and US Air Force Successfully Fly F-16 Fighter Jet Under Full AI Control](https://www.wortins.com/story/darpa-and-us-air-force-successfully-fly-f-16-fighter-jet-und-b659da37) — [DARPA](https://www.darpa.mil/news/2026/darpa-us-air-force-fly-ai-controlled-f-16)

---

_Curated and written by [Wortins](https://www.wortins.com) — The daily AI briefing. Every story links to its original source; the "Wortins read" on each is our own original analysis. [About Wortins & our editorial approach](https://www.wortins.com/about)._
