logo

Hackers exploit critical bug in Array Networks SSL VPN products

ID: 1a49f54f-5643-51fc-bc0d-385d3f928582

STIX ID: report--1a49f54f-5643-51fc-bc0d-385d3f928582

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-11-26

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A critical RCE vulnerability (CVE-2023-28461, CVSS 9.8) affecting Array Networks AG and vxAG SSL VPN appliances (versions ≤ 9.4.0.481) is being actively exploited; CISA added it to the Known Exploited Vulnerabilities catalog and urges federal agencies and critical infrastructure operators to apply vendor patches (9.4.0.484) or mitigations by the specified deadline. The flaw allows unauthenticated filesystem browsing or remote code execution via the HTTP header "flags" attribute; vendor mitigations exist but may impact client security and portal functionality and should be tested before deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.