Two AI Infrastructure Tools Just Landed in KEV With Three-Day Deadlines. That's Not a Coincidence Anymore. | Vulnerabilities.ai™ Research
← Research
August 31, 2026 · KEV & AI Infrastructure
Cross-cutting

Two AI Infrastructure Tools Just Landed in KEV With Three-Day Deadlines. That's Not a Coincidence Anymore.

CVE
Tool
KEV added
Deadline
CVE-2026-9198
Langflow
August 5, 2026
Compressed
CVE-2025-62593
Ray
August 17, 2026
3 days

On August 5, CISA added a code injection flaw in Langflow — an open-source AI application development platform — to its Known Exploited Vulnerabilities catalog. On August 17, it added a separate flaw in Ray, the distributed compute engine that underpins a large share of production machine learning training and inference infrastructure, worldwide. Neither addition made much noise on its own. Together, they're the clearest sign yet that AI-specific infrastructure has become a real, active exploitation target — and that BOD 26-04's own risk model is already treating it that way.

What actually happened, in each case

Langflow's flaw, CVE-2026-9198, is a code injection vulnerability letting an unauthenticated attacker achieve full remote code execution on a default Langflow deployment — no special access required, no user interaction needed. It had been fixed in July, but CISA's KEV addition on August 5 confirmed active exploitation was already underway; telemetry from KEVIntel recorded 650 exploitation attempts from 244 unique attacker IP addresses across 41 countries, starting the month before the flaw was even patched.

Ray's flaw, CVE-2025-62593, is a code injection vulnerability in a tool with a much larger and much less visible footprint. Ray isn't typically something an organization formally procures — it arrives as a transitive dependency, a layer baked into a base container image, a component bundled inside a managed ML platform, or something a data scientist installs directly via pip on a laptop. That makes it a tool that shows up in the inventories of several different teams at once, or in none of them, which is precisely the shadow-IT pattern that makes a flaw like this dangerous well beyond its technical severity.

Why the deadlines are the real story

Both flaws received compressed remediation windows under BOD 26-04's risk-tiered model, which replaced the old flat fourteen-day KEV clock with deadlines scaled to actual risk — vulnerabilities on publicly exposed assets that grant total control post-exploitation get the shortest windows of all. Ray's federal remediation deadline was three days from the KEV addition. That's the same tier BOD 26-04 reserves for the most dangerous class of exposure it tracks, now being applied to core AI training and inference infrastructure specifically, not just the traditional perimeter and identity systems the directive was originally built around.

Why two data points, two weeks apart, matter more than either alone

A single AI-tool KEV addition could be a one-off. Two, in the same category of severity, in the same compressed-deadline tier, roughly two weeks apart, is the beginning of a pattern — and it's a pattern that sits exactly at the intersection this site exists to track. It's not just that AI systems are getting attacked; it's that the specific infrastructure organizations use to build and run AI — orchestration platforms, distributed compute engines, the tooling layer beneath the models themselves — is becoming an actively exploited target category in its own right, subject to the same binding federal urgency as any other critical infrastructure flaw. For an organization trying to inventory its actual AI exposure, Ray's arrival pattern is the sharper warning of the two: a tool this deeply embedded, this rarely formally tracked, is exactly the kind of asset an organization can be compelled to patch in three days without first knowing it's running.

Sources
Verified CISA, Known Exploited Vulnerabilities Catalog, entries for CVE-2026-9198 and CVE-2025-62593.
Reported The Hacker News, "CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited," August 5, 2026.
Reported ComplianceHub.Wiki, "CISA Put an AI Compute Framework in the KEV Catalog and Gave Agencies Three Days," August 17, 2026.
This brief synthesizes and cross-verifies publicly available primary and secondary sources, listed above. It is independent analysis, not first-party research.