High severity7.2CISA KEVNVD Advisory· Published Dec 5, 2025· Updated Jun 17, 2026
CVE-2025-66644
CVE-2025-66644
Description
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<9.4.5.9+ 1 more
- (no CPE)range: <9.4.5.9
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
4- www.jpcert.or.jp/at/2025/at250024.htmlnvdThird Party Advisory
- x.com/ArraySupport/status/1921373397533032590nvdThird Party Advisory
- www.bleepingcomputer.com/news/security/hackers-are-exploiting-arrayos-ag-vpn-flaw-to-plant-webshells/nvdPress/Media Coverage
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.