CISA Adds Actively Exploited Ray AI Framework Flaw to Must-Patch List

The bug in Ray, a popular open-source tool for running AI workloads, is being abused in the wild. CISA gave federal agencies a deadline to fix it.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A server room filled with blinking network equipment and cooling systems, with red warning lights illuminating the hardware, suggesting active threat detection
Share

Key points

  • The U.S. Cybersecurity and Infrastructure Security Agency added a critical Ray vulnerability to its Known Exploited Vulnerabilities catalog on Monday.
  • Ray is an open-source framework used by companies to run large artificial intelligence and machine learning jobs across many machines.
  • CISA says the flaw is already being exploited in real attacks, though it has not named the groups behind them.
  • Federal agencies must patch or stop using affected Ray installations under CISA's binding directive.
  • Security researchers previously tracked an exploitation campaign against exposed Ray clusters called ShadowRay.

The U.S. Government's cyber agency is telling federal departments to patch a serious flaw in Ray, an open-source tool that companies use to run AI workloads across many computers at once.

CISA added the bug to its Known Exploited Vulnerabilities catalog on Monday. That list is reserved for flaws where the agency has confirmed active attacks, not just theoretical risk. This is the latest in a run of catalog additions we've reported this month, including a critical Langflow flaw and Apache Tomcat on 5 August.

What is Ray and why does this matter?

Ray is a Python-based framework that spreads AI and machine learning jobs across a cluster of machines. Training a large model on a single server is slow; Ray lets a company direct dozens or hundreds of machines at the same job simultaneously.

It's widely deployed inside major AI labs and cloud providers. If an attacker breaks into a Ray cluster, they land on machines that often hold model weights, API keys and cloud account credentials.

How are attackers exploiting it?

Attackers are hitting Ray installations exposed to the internet without authentication, then running their own code on the servers. They find a Ray dashboard sitting open online, send a crafted request, and the server runs whatever it's told.

Researchers at Oligo Security documented a long-running campaign against exposed Ray clusters, which they named ShadowRay. That campaign has been used to steal cloud credentials and install cryptocurrency miners on victim machines. Attribution to a specific named group is thin. I'd put the ShadowRay cluster at medium confidence as financially motivated, given the mining payloads, with no strong nation-state overlap reported so far.

Capability and intent aren't the same thing. Remote code execution on AI infrastructure would be attractive to espionage groups too. The observed intent so far looks criminal.

Who needs to act?

Who What to do Deadline
U.S. Federal civilian agencies Patch or remove affected Ray systems Set by CISA directive
Private companies running Ray Update to the latest version and take dashboards off the public internet As soon as possible
Cloud teams using managed AI platforms Confirm with the provider whether Ray is patched Ongoing

Should ordinary people worry?

Not directly. This is an infrastructure bug, not a consumer product flaw. You won't be prompted to update anything on your phone.

The indirect risk is more interesting. Companies training AI models on Ray sometimes hold customer records as training input. A breach at that layer could surface later as a phishing campaign or a leaked dataset.

If you work in IT at an organisation that runs Ray, the steps are straightforward. Update to the fixed release. Put the Ray dashboard behind a login and a private network. Treat any Ray instance that's faced the open internet as already probed.

CISA's catalog listing gives federal agencies a hard deadline. For everyone else, the deadline is whenever attackers get around to you.

© 2026 Threat Vectr