CISA has ordered US federal civilian agencies to remediate a critical vulnerability in Ray within three days after saying attackers are exploiting it in the wild, The Register reports. The bug, tracked as CVE-2025-62593, is a remote-code-execution flaw in the open-source framework used to scale Python and machine-learning workloads. According to The Register, the vulnerability was first disclosed in November 2025 and carries a 9.4 severity rating under CVSS v4. Ray 2.52.0 fixes the flaw. The unusual part is the deadline: CISA gave federal civilian executive branch agencies three days to act, rather than the standard 14-day remediation window. The Register says CISA did not explain why it imposed the shorter window. The agency’s catalog field for whether the vulnerability is known to be used in ransomware campaigns was marked “unknown,” according to the report. The Register notes that Binding Operational Directive 26-04 allows CISA to set a three-day deadline for vulnerabilities it considers especially risky. The attack mechanism is tied to how vulnerable Ray versions attempted to block browser-originated requests. The Register reports that affected versions checked whether a request’s User-Agent header began with “Mozilla.” Firefox and Safari, however, allow scripts using the Fetch API to modify that header, creating a path for browser-based exploitation. In the scenario described by Ray’s developers and reported by The Register, a developer running Ray in a development or test environment could be compromised by visiting a malicious website or being served a malicious advertisement in an affected browser. The attacker could then use DNS rebinding to reach the local Ray service and execute arbitrary shell code on the developer’s machine. The same pattern can extend beyond a single laptop or workstation. The Register reports that the browser can be used as an intermediary to target Ray instances that are adjacent on a private corporate network, widening the risk from local development environments to internal systems that may not be exposed directly to the public internet. Ray’s exposure matters because it sits in the AI and Python infrastructure stack. The framework helps developers move workloads from local development to clusters with relatively small code changes, and The Register says it is used or supported by companies including Amazon, Apple, and OpenAI. The project began at UC Berkeley, was commercialized through Anyscale, and is now managed by the Linux Foundation’s PyTorch Foundation, according to the report. The Register also cites adoption figures that suggest a broad potential blast radius. Anyscale’s figures as of October 2025 put Ray at more than 237 million total downloads and 7 million weekly downloads. NextSprints estimated 1 million monthly active users and use by 60% of Fortune 500 companies, according to the same report. The underlying security issue is also architectural. The Register reports that Ray’s advisory pointed to the project’s longstanding lack of authentication on critical endpoints, reflecting a model that assumed clusters would run inside trusted, isolated networks. Ray 2.52.0 introduced optional token-based authentication as an added control, but it remains disabled by default, and the project continues to recommend controlled network deployment rather than treating authentication as a substitute for isolation. Who benefits: Attackers benefit from a path that can start with phishing or malvertising and move toward local or internal Ray services. Security teams benefit from a clear fixed version: Ray 2.52.0. Who's exposed: Federal civilian agencies running vulnerable Ray versions are directly exposed to CISA’s three-day clock. Companies using Ray in development, testing, or private network environments should also treat the reported attack path as relevant, especially where Firefox or Safari may be in use.