CVE-2025-62593Active Exploitation(anyscale / ray)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 29 mentions and remains active

Immediate actions

  • Patch anyscale ray systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-20. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-94CWE-352

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ray

Threat summary

  • Active exploitation appears in 43 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 64 mentions across 12 observed days

What's happening

  • Active exploitation reported across 43 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 30 signals
  • Technical details provided in 52 signals
  • Disclosure: 8 classified signals
  • Peaked 10d ago at 29 mentions (2026-08-18); latest day: 1
  • 64 total mentions across 12 days

Affected systems

Vendors
Products
ray

Deep dive

Activity timeline64 mentions / 12d
07152229Mentions · 2026-08-17: 9Mentions · 2026-08-18: 29Mentions · 2026-08-19: 12Mentions · 2026-08-20: 3Mentions · 2026-08-21: 2Mentions · 2026-08-22: 1Mentions · 2026-08-23: 2Mentions · 2026-08-24: 2Mentions · 2026-08-27: 1Mentions · 2026-08-28: 1Mentions · 2026-09-07: 1Mentions · 2026-09-24: 1PoC Mentioned / Linked · 2026-08-17: 3PoC Mentioned / Linked · 2026-08-18: 3PoC Mentioned / Linked · 2026-08-19: 2PoC Mentioned / Linked · 2026-08-23: 1Exploit Tool / Code · 2026-08-17: 1Exploit Tool / Code · 2026-08-19: 1Exploit Tool / Code · 2026-08-21: 1Active Exploitation · 2026-08-17: 7Active Exploitation · 2026-08-18: 20Active Exploitation · 2026-08-19: 8Active Exploitation · 2026-08-20: 2Active Exploitation · 2026-08-21: 1Active Exploitation · 2026-08-22: 1Active Exploitation · 2026-08-23: 1Active Exploitation · 2026-08-24: 1Active Exploitation · 2026-08-27: 1Active Exploitation · 2026-09-07: 1Patch / Workaround · 2026-08-17: 2Patch / Workaround · 2026-08-18: 16Patch / Workaround · 2026-08-19: 4Patch / Workaround · 2026-08-20: 3Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-08-23: 2Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-08-27: 1Technical Details · 2026-08-17: 8Technical Details · 2026-08-18: 24Technical Details · 2026-08-19: 8Technical Details · 2026-08-20: 3Technical Details · 2026-08-21: 1Technical Details · 2026-08-23: 2Technical Details · 2026-08-24: 2Technical Details · 2026-08-27: 1Technical Details · 2026-08-28: 1Technical Details · 2026-09-07: 1Technical Details · 2026-09-24: 108-1708-1808-1908-2008-2108-2208-2308-2408-2708-2809-0709-24
Signal classification5 categories
Active Exploitation
4265.6%
Patch
914.1%
Disclosure
812.5%
General
46.3%
PoC
11.6%
Referenced assets50 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-179
Active Exploitation7Disclosure1Patch1
2026-08-1829
Active Exploitation19Disclosure5General1Patch4
2026-08-1912
Active Exploitation8General2Patch1PoC1
2026-08-203
Active Exploitation2Patch1
2026-08-212
Active Exploitation1General1
2026-08-221
Active Exploitation1
2026-08-232
Active Exploitation1Patch1
2026-08-242
Active Exploitation1Patch1
2026-08-271
Active Exploitation1
2026-08-281
Disclosure1
2026-09-071
Active Exploitation1
2026-09-241
Disclosure1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ An actively exploited Ray flaw can lead to browser-based RCE. CISA has added CVE-2025-62593 to its KEV catalog. The documented attack path uses DNS rebinding and requires a developer running Ray to visit a malicious site or be served a malicious ad in Firefox or Safari. See how the attack works: https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html

    Post summary

    CISA has flagged CVE‑2025‑62593 as an actively exploited Ray vulnerability involving DNS rebinding, leading to browser‑based RCE, but no PoC, patch or mitigation details are provided.

    8220981931.3K
    2.4M followersView on X
  • FOFA@fofabot
    Active Exploitation

    ⚠️⚠️ CVE-2025-62593 (CVSS 9.4, KEV): Unauthenticated server-side RCE on exposed Ray Dashboards, reachable via DNS rebinding in Firefox/Safari. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJSYXktRGFzaGJvYXJkIg== 🎯1M+ Results are found on http://en.fofa.info. FOFA Query: app="Ray-Dashboard" 🔖Refer: https://thehackernews.com/2026/08/18/cisa-flags-actively-exploited-ray-flaw.html #OSINT #FOFA #CyberSecurity #Vulnerability #Ray

    Post summary

    The post highlights CVE-2025-62593 as an unauthenticated RCE on Ray Dashboards with a high CVSS score, and confirms it is being actively exploited as per CISA’s KEV status.

    11003274.7K
    14.8K followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    🚨 CISA Confirms Active Exploitation of Critical Ray AI Framework Vulnerability CISA has added **CVE-2025-62593**, a critical code-injection vulnerability affecting the Ray distributed computing framework, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming exploitation in the wild. * CVE-2025-62593 affects Ray and can enable arbitrary code execution in vulnerable environments * The flaw involves insufficient protection against browser-based attacks and can be abused through DNS rebinding techniques * An attacker can potentially reach unauthenticated Ray job-submission interfaces and execute code with the privileges of the Ray process * CISA added the vulnerability to the KEV Catalog on August 17, 2026 * U.S. federal civilian agencies have been given an accelerated remediation deadline of August 20, 2026, highlighting the urgency of the active exploitation risk. * Ray is widely used for distributed Python workloads, AI/ML processing and large-scale compute environments, making exposed or improperly secured deployments particularly attractive targets ⚠️ Analyst Note: This vulnerability is especially relevant to AI infrastructure because Ray is frequently used to orchestrate high-value compute resources, including GPU-heavy environments. Successful exploitation may therefore provide attackers with access not only to servers but potentially to AI workloads, model data and expensive compute capacity. Organizations using Ray should prioritize upgrading vulnerable deployments and ensure management interfaces are not unnecessarily exposed. Source: CISA https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog CISA KEV Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog #DDW #CyberSecurity #CISA #AI

    Post summary

    CISA confirms CVE‑2025‑62593 is actively exploited in the wild, urging immediate remediation of Ray deployments.

    1402266.7K
    205.0K followersView on X
  • CISA Cyber@CISACyber
    Patch

    🛡️We added CVE-2025-62593, a critical code injection #RCE vulnerability affecting Ray-Project Ray, to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec https://t.co/hcKeyl36te

    Post summary

    The tweet announces that CVE‑2025‑62593—a critical RCE code injection flaw in Ray‑Project Ray—has been added to the DHS KEV catalog and urges organizations to apply mitigations to defend against potential attacks.

    1502348.6K
    302.8K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-62593 - critical 🚨 Ray < 2.52.0 - Remote Code Execution > Ray versions prior to 2.52.0 allow unauthenticated remote code execution via the job ... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-62593 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2025-62593 as a critical unauthenticated RCE in Ray versions prior to 2.52.0 and references a Nuclei template, but it lacks explicit PoC, exploit tooling, active exploitation, or remediation instructions.

    050197663
    1.3K followersView on X
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    Active Exploitation

    CVSS 9.4が1本ある。国内大手2社のデータが漏れ、AIがAIを攻撃した。 開発環境もAIツールも、今から君が守るものだ。 ・Ray CVE-2025-62593(CVSS 9.4)、AI開発基盤にブラウザ経由RCE——KEV追加 ・日本交通に2.9TB窃取、ドライバー処分歴など機微情報が流出か ・M365 Copilot、隠しパラメータでガードレール突破——パスワード窃取 ・OpenAI自社AIがHugging Faceを攻撃、AI攻撃防止策10選を公開 ・ANAグループOCS、脆弱性悪用の不正アクセスで個人情報漏洩か ・GitLab CVE-2026-19478、未認証でプロジェクト削除可能 今日の6本に共通しているのは一つだ。 「使っているツールが入口になった」—— 君の組織で、これを誰がセキュリティの目で見ている?

    Post summary

    The tweet highlights active exploitation of CVEs (notably Ray CVE-2025-62593 and GitLab CVE-2026-19478) with high CVSS scores and real‑world data breaches, yet offers no PoC details or patch information.

    0102092.0K
    1.7K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(08/17追加) #vulnerability 🛡CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability ✅概要 ・深刻度:緊急 9.4 (CVSS Base) / GitHub (CNA) ・種別:コード・インジェクション (CWE-94) / クロスサイトリクエストフォージェリ (CWE-352) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Ray 2.52.0 未満に存在する、ブラウザ経由の攻撃に対する防御不備に起因するリモートコード実行の脆弱性です。 Ray は User-Agent ヘッダーが Mozilla で始まることを防御条件としていましたが、Fetch仕様では User-Agent ヘッダーを変更できるため、この防御は不十分です。 DNS rebinding 攻撃と組み合わせることで、開発者が Firefox または Safari で悪意あるWebサイトやマルバタイジングを閲覧した際に、Ray 上で任意コード実行につながる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅CISA 評価 ・攻撃自動化:自動化は困難 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月20日 ・BOD 26-04 対処期限(露出なし):2026年8月31日 ✅攻撃前提条件 ・Ray 2.52.0 未満を使用している ・開発者環境またはRay環境でRayが起動している ・Rayの関連エンドポイントへブラウザ経由で到達可能である ・被害者がFirefoxまたはSafariで悪意あるWebサイトを閲覧する、またはマルバタイジングを表示する ・DNS rebinding 攻撃が成立するネットワーク条件である ・Ray 2.52.0 以降へ更新されていない ✅悪用時影響 ・Ray環境上で任意コードを実行される可能性がある ・開発者端末またはRay実行環境上のファイルや認証情報へアクセスされる可能性がある ・AI/ML開発環境、ジョブ実行環境、クラスタ構成情報を侵害される可能性がある ・環境変数、APIキー、クラウド認証情報などを窃取される可能性がある ・Ray環境を起点に追加侵害へつなげられる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:確認済み(Bitsight) ・概要:Bitsight は、RondoDox botnet が CVE-2025-62593 を悪用対象に含めていたことを確認 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2025-62593 ・https://www.cve.org/CVERecord?id=CVE-2025-62593 ・https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v ・https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09 ・https://github.com/cisagov/vulnrichment/blob/develop/2025/62xxx/CVE-2025-62593.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-62593 ・https://www.bitsight.com/blog/rondodox-botnet-infrastructure-analysis ・https://jvndb.jvn.jp/ja/cwe/CWE-94.html ・https://jvndb.jvn.jp/ja/cwe/CWE-352.html CISA Alert ・https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    CISA added CVE-2025-62593 to its KEV catalog and Bitsight confirms the RondoDox botnet is actively exploiting it, with publicly available PoC code.

    0301026.4K
    44.3K followersView on X
  • moton@moton
    Active Exploitation

    CVE-2025-62593: Ray RCE Exploited in the Wild - https://securityonline.info/cve-2025-62593-ray-rce/

    Post summary

    CVE-2025-62593, a remote code execution vulnerability in Ray, is reportedly being exploited in the wild, but the brief post provides no PoC, exploit code, patch details, or in‑depth technical data.

    00081316
    757 followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    1/4 🚨 24h Cyber Alert – Aug 18 CISA just dropped a new KEV + flagged a Windows flaw as ransomware-used. Ray RCE. Task Host → SYSTEM. WMIC killed. Azure dumps for sale. Cl0p back. This is the one you save. Full breakdown + actions ↓ 2/4 New KEV: CVE-2025-62593 – Ray (AI compute) code injection RCE Added yesterday. Due Aug 20. CISA also updated CVE-2025-60710 (Windows Task Host) → now confirmed ransomware abuse. Microsoft just removed WMIC (the LOLBIN ransomware uses to kill shadows + AV). Sources: CISA + BleepingComputer (Aug 17-18) 3/4 Active right now: • TheHatman selling 3.6M+ Azure employee records (McD, Gap, Vodafone, TCS…) • Cl0p listing GE + Philips (PTC Windchill path) • Pokémon Center hit via third-party logistics • French tax authority – 678k records stolen Credential + supply-chain pressure is elevated. 4/4 Do this today: ✅ Patch Ray + confirm Task Host (CVE-2025-60710) ✅ Hunt Azure for password spray + MFA fatigue ✅ Check PTC Windchill/FlexPLM for webshells ✅ Kill remaining WMIC usage Bookmark this. RT so your team sees it before the next wave. What’s the first thing you’re checking this morning? #CyberSecurity #KEV #Ransomware #CISA

    Post summary

    The tweet reports that CISA has identified CVE‑2025‑62593 and CVE‑2025‑60710 as KEVs with active ransomware exploitation, and urges immediate patching and mitigation steps.

    32000275
    12.4K followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Disclosure

    localhost にしか bind していないから安全、が通じない話。Ray CVE-2025-62593 の仕組みを DNS リバインディングから読み解いて、venv を横断して該当バージョンを洗い出す依存なしの判定スクリプトまで書きました。 https://blog.hashito.biz/2026/08/18/ray-cve-2025-62593-dns-rebinding-localhost-rce/

    Post summary

    The blog explains how Ray CVE‑2025‑62593 can be exploited via DNS rebinding and presents a script that detects vulnerable versions, refuting the assumption that localhost binding alone guarantees safety.

    01110410
    563 followersView on X
  • Cybersecurity News Alerts@secureblognews
    Disclosure

    Is your AI infrastructure exposed? 🛑 A critical vulnerability (CVE-2025-62593) in the Ray AI framework allows attackers to hijack machine learning clusters. Secure your workloads: https://cyberupdates365.com/ray-ai-vulnerability-cve-2025-62593/ #AI #MLOps #CVE202562593 #technews

    Post summary

    The post announces CVE‑2025‑62593, warns that it enables attackers to hijack Ray AI clusters, and urges users to secure their workloads.

    0003040
    41 followersView on X
  • Noor@noorchronicle
    General

    NOOR Threat Feed Brief Here are the summarized CVEs, prioritized by real-world exploitation risk: 1. **CVE-2026-33824 (High Risk)**: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability - allows remote code execution. 2. **CVE-2025-62593 (High Risk)**: Ray-Project Ray Code Injection Vulnerability - allows remote code execution through Firefox and Safari. 3. **CVE-2026-55040 (Medium-Moderate Risk)**: Microsoft SharePoint Weak Authentication Vulnerability - allows unauthorized bypass of security features over a network. 4. **CVE-2026-65400 (Medium-Moderate Risk)**: Apple macOS Improper Authentication Vulnerability - allows an attacker to authenticate to Screen Sharing without valid credentials. 5. **CVE-2026-59310 (Medium Risk)**: Broadcom VMware vCenter Path Traversal Vulnerability - allows a threat actor with network access to execute arbitrary code. Note: The risk level is subjective and based on general exploitation trends. Real-world exploitation risk can vary depending on specific circumstances.

    Post summary

    The feed lists several CVEs with risk ratings and brief technical descriptors but does not include PoCs, exploit code, or patch information.

    0101091
    56 followersView on X
  • Decryption Digest ®@DecryptionDigst
    Active Exploitation

    CISA KEV ALERT: CVE-2025-62593 (CVSS 9.4) in Ray 200,000 clusters open to pre-auth RCE. Federal patch deadline: August 20. ShadowRay 2.0 is mining NVIDIA A100s and stealing model weights. Patch: Ray 2.52.0. Block 8265/8266. Hunt kworker/0:0. #CVE202562593 #RayRCE #CISAAlert https://t.co/8riingJklD

    Post summary

    The alert announces CVE-2025-62593 as a high‑severity RCE affecting ~200,000 Ray clusters, reports active exploitation by ShadowRay, and cites an available patch.

    1001031
    28 followersView on X
  • cyber_updates_365@CyberUpdates365
    Patch

    Running Ray for your ML pipelines? 🚨 CVE-2025-62593 puts your entire AI cluster at risk of Remote Code Execution. See how to isolate and patch your framework today: https://cyberupdates365.com/ray-ai-vulnerability-cve-2025-62593/ #CyberSecurity #cybernews #latestupdates #newsfile

    Post summary

    CVE‑2025‑62593 poses a Remote Code Execution risk to Ray AI clusters; the post emphasizes the need to isolate and apply a patch to protect the framework.

    0002033
    16 followersView on X
  • Shuvo@suvobgd
    Active Exploitation

    Defending Distributed AI Environments Against Active Exploitation of the Ray Code Injection Vulnerability (CVE-2025-62593) https://ixuvo.com/blog/defending-ray-clusters-cve-2025-62593-security

    Post summary

    The blog post focuses on defensive strategies for Ray clusters under threat from a known active code injection vulnerability (CVE‑2025‑62593), discussing how to mitigate ongoing attacks.

    0000168
    195 followersView on X
  • Shuvo@suvobgd
    Active Exploitation

    Defending Distributed AI Environments Against Active Exploitation of the Ray Code Injection Vulnerability (CVE-2025-62593) https://ixuvo.com/blog/defending-ray-clusters-cve-2025-62593-security

    Post summary

    The article highlights that CVE-2025-62593 is actively exploited in Ray clusters and discusses defense strategies, although it does not detail any specific mitigation or patch.

    0000145
    194 followersView on X
  • Total Cyber-Sec@totalcybersec
    Active Exploitation

    1/8 🔥 CISA confirmó explotación activa de CVE-2025-62593 en Ray. El botnet RondoDox, inspirado en Mirai, la utiliza dentro de un arsenal de 174 exploits para comprometer dispositivos expuestos. Parchar tarde ya equivale a dejar una puerta abierta.

    Post summary

    CISA reports that CVE-2025-62593 is being actively exploited by the RondoDox botnet; the post stresses the importance of timely patching to close the vulnerability.

    1000049
    15.8K followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-IxgnwCb [CRITICAL/PoC] Linked: CVE-2025-62593 CVE-2025-62593-PoC 🔗 https://exploitgrid.net/exploits/549943ae-321f-4b7f-b86d-87b518ed82fc

    Post summary

    The content announces a proof‑of‑concept for CVE‑2025‑62593, providing a link to the exploit code stored on ExploitGrid, with no indications of active exploitation or remediation.

    1000031
    35 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: EGE-GH-bnhF7il ( CVE-2020-14882 ) EGE-GH-seDznkg ( CVE-2026-65400 ) EGE-GH-voHnlXt ( CVE-2026-15748 ) EGE-GH-UkSlg0M ( CVE-2026-19598 ) EGE-GH-IxgnwCb ( CVE-2025-62593 ) ..🧵👇

    Post summary

    The digest simply lists several CVE identifiers without providing any exploitation details, patches, or technical context.

    1000056
    35 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2025-62593 in Ray is actively exploited and CISA KEV-listed. A DNS rebinding and User-Agent bypass chain lets a malicious webpage submit jobs to a local Ray Dashboard, achieving RCE without credentials. Key findings: - CVE-2025-62593 (CVSS 4.0: 9.4 Critical, CVSS 3.1: 8.8 High) affects all Ray PyPI versions before 2.52.0. The Jobs API at /api/jobs/ required no authentication, and the only browser guard checked whether the User-Agent started with "Mozilla". Firefox and Safari allow JavaScript to override that header, so sending "User-Agent: Other" bypasses the check entirely. Chrome blocks the override, making it resilient to this specific path. - The six-stage chain: victim visits attacker page, DNS rebinding resolves the attacker domain to 127.0.0.1:8265, browser POSTs to /api/jobs/ with a forged User-Agent, Ray accepts the job, and the entrypoint executes with Ray process privileges. Post-exploitation targets cloud credentials, SSH keys, model artifacts, training data, and GPU resources for mining or lateral movement. - For responders hunting exploitation: look for POST requests to /api/jobs/ with non-Mozilla User-Agent strings, Ray worker processes spawning unexpected shells or interpreters, and DNS telemetry showing short-TTL domains that flip between external IPs and loopback. Check EDR for unusual child processes under Ray and unexplained outbound connections. #DFIR_Radar

    Post summary

    CVE-2025-62593 is actively exploited in the wild, with detailed chain analysis and evidence of CISA KEV listing, but no specific patch or exploit code is provided.

    10000161
    1.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanyscaleray---

Explore more