logo

Hackers are exploiting ArrayOS AG VPN flaw to plant webshells

ID: ffb7bc34-3893-50a8-86ce-b115f3a6221e

STIX ID: report--ffb7bc34-3893-50a8-86ce-b115f3a6221e

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-12-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

JPCERT/CC warns that threat actors have been exploiting a command-injection vulnerability in Array Networks AG Series VPN appliances (ArrayOS AG ≤ 9.4.5.8) to drop PHP webshells and create rogue users, with observed attacks since at least August primarily targeting organizations in Japan and attacker activity tied to IP 194.233.100.138; Array released version 9.4.5.9 with a fix and recommends disabling DesktopDirect or blocking semicolon-containing URLs as mitigations when patching is not possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.