Skip to content
Hackers Exploit ArrayOS AG VPN Vulnerability to Deploy Webshells

Hackers Exploit ArrayOS AG VPN Vulnerability to Deploy Webshells

First seen 5 Dec 2025, 13:44 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Threat actors are exploiting a command injection vulnerability in ArrayOS AG VPN devices to deploy webshells and create unauthorized user accounts. The vulnerability has been actively targeted since at least August 2025, affecting various organizations. Array Networks issued a security update in May 2025 to address the flaw, but it remains untracked due to the lack of an assigned identifier.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (4)

Following this threat?

Track ArrayOS AG and CVE-2023-28461 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed