Hackers Exploit ArrayOS AG VPN Vulnerability to Deploy Webshells

Hackers Exploit ArrayOS AG VPN Vulnerability to Deploy Webshells

First seen 5 Dec 2025, 13:44 UTC BleepingcomputerCybersecuritynewsGbhackersCyberpress 38.3

Article Content

Browse articles
ThreatCluster

Threat actors are exploiting a command injection vulnerability in ArrayOS AG VPN devices to deploy webshells and create unauthorized user accounts. The vulnerability has been actively targeted since at least August 2025, affecting various organizations. Array Networks issued a security update in May 2025 to address the flaw, but it remains untracked due to the lack of an assigned identifier.