
CISA Gave 3 Days to Patch Ray. Auth Is Still Off by Default.
CISA gave federal agencies until August 20 to patch CVE-2025-62593 in Ray. The 2.52.0 fix blocks a browser attack and leaves the Jobs API unauthenticated — and the CVSS 10.0 filed against that default was rejected by NVD, so no scanner will ever show it to you.
August 19, 2026 · 12 min read