Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw Found in Ray AI Software Used by Developers

A critical security vulnerability has been found in the Ray AI compute engine software used by developers. This flaw could allow attackers to run harmful code on a developer’s computer if they visit a malicious website. The issue has been fixed in the latest software update, and organisations using Ray should update immediately to protect themselves.

18 August 2026

Reference: CVE-2025-62593

1. What is being reported?

The Ray AI software, used by developers for computing tasks, has a serious security weakness. It relies on a weak method to check web browsers, which attackers can bypass using a special technique involving malicious websites. This allows attackers to run harmful commands on the developer’s machine without permission. The problem affects versions before 2.52.0 and has been fixed in that version.

2. What this means in plain English

If your organisation uses Ray software for AI development, an attacker could exploit this flaw to take control of a developer’s computer by tricking them into visiting a harmful website or seeing a malicious advertisement. This could lead to data theft, disruption, or further attacks on your systems.

3. Could this affect a small business?

Small businesses or charities that do not use Ray software or do not have developers working with it are unlikely to be affected. However, if your organisation uses Ray for AI development or computing tasks, you should take this seriously and act quickly.

4. What to do now

  • Check if your organisation uses Ray software and identify the version installed.
  • If Ray is used, ensure it is updated to version 2.52.0 or later immediately.
  • Avoid visiting unknown or untrusted websites, especially on machines running Ray.
  • Ask your IT provider to confirm that all mitigations and patches recommended by the vendor and security authorities are applied.

5. Ask your IT provider

Can you confirm whether we use Ray AI software, and if so, have we updated it to version 2.52.0 or later to fix the critical security vulnerability CVE-2025-62593?

6. Bottom line

If you use Ray AI software, update it now to prevent attackers from exploiting a critical security flaw.

Information based on CISA KEV, NVD and reputable security reporting.

Back to Vulnerability Briefs