logo

JPCERT/CC Reports Widespread Exploitation of Array Networks AG Gateway Vulnerability

ID: 2a7bb169-9975-5b80-8b84-f71b6f2efb30

STIX ID: report--2a7bb169-9975-5b80-8b84-f71b6f2efb30

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2025-12-05

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

JPCERT/CC warns that a command-injection flaw in Array Networks’ AG Series DesktopDirect (affecting ArrayOS AG ≤ 9.4.5.8) has been exploited in the wild since August 2025—despite a vendor patch (9.4.5.9) issued in May 2025—and has been used to install webshells, create accounts, and intrude into internal networks; observed attack traffic was traced to IP 194.233.100.138 and organizations are urged to investigate, patch, and apply mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.