CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2025-62593, a Ray-Project Ray code injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. This type of vulnerability is a common attack method used by malicious actors and presents considerable risks. Binding Operational Directive (BOD) 26-04 mandates vulnerability management for Federal Civilian Executive Branch agencies. This directive emphasizes the KEV Catalog and requires agencies to quickly fix high-risk vulnerabilities on public assets that offer complete control after exploitation. Lower-risk vulnerabilities can be addressed later. BOD 26-04 also sets requirements for agencies to check for system compromise before applying patches. Although BOD 26-04 is for federal agencies, CISA urges all organizations to use risk-based vulnerability management and fix KEV Catalog items. CISA will continue to add vulnerabilities that meet their criteria to the catalog. Organizations can nominate exploited vulnerabilities not yet in the KEV Catalog via a nomination form, provided they have a CVE ID, exploitation evidence, and clear mitigation steps.