The US government's top cyber agency just confirmed hackers are actively exploiting a hole in Ray, the open-source engine quietly running much of the world's AI infrastructure.
On August 17, the Cybersecurity and Infrastructure Security Agency added a vulnerability in Ray to its Known Exploited Vulnerabilities catalogue. That listing is CISA's official confirmation that attackers are using the flaw in real-world attacks, not just a theoretical risk. Federal agencies now have three days to patch affected systems, a compressed deadline CISA reserves for vulnerabilities it considers actively dangerous. Ray itself is a widely used framework for distributing AI training and inference workloads across clusters, which is why a single flaw in it carries outsized reach.
Ray sits underneath a lot of AI infrastructure that never makes headlines - it is the orchestration layer, not the flashy model on top. A flaw there does not just expose one company's app; it potentially exposes every unpatched cluster running Ray, from research labs to startups to large enterprises. A three-day patch window is CISA's way of saying this is not a routine advisory.
KEV additions like this one are a useful reminder that the AI boom's plumbing runs on the same open-source code, with the same kinds of bugs, as everything else.