LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-66644: Array Networks ArrayOS AG OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 8, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 29, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-66644 to its Known Exploited Vulnerabilities catalog on Dec 8, 2025, with a federal patch deadline of Dec 29, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.

Array Networks ArrayOS AG contains an OS command injection vulnerability tracked as CVE-2025-66644. An attacker who can reach the affected component may be able to execute arbitrary operating-system commands on the appliance.

This class of flaw is serious on network devices because successful exploitation can grant control over traffic inspection, authentication, and connected services. Organizations that rely on Array Networks gateways should treat the issue as a priority for inventory and remediation.

How it works

The weakness is categorized as CWE-78, improper neutralization of special elements used in an OS command. The vulnerable code constructs operating-system commands from untrusted input without adequate escaping or validation.

Am I affected? How to find it in your systems

ArrayOS AG runs on Array Networks hardware appliances used for load balancing, VPN, and application delivery. Begin by locating all deployed instances through asset-management records, network discovery, or configuration-management databases.

How to remediate

Apply the vendor-supplied update referenced in the official advisory. Patching eliminates the root cause and is the primary control.

If you can't patch immediately

Until a patch can be applied, reduce exposure by following the mitigations prescribed by the vendor. CISA also directs agencies to apply applicable guidance from BOD 22-01 for cloud-connected services or to discontinue use of the product if mitigations are unavailable.

If your data may have been exposed

Command-injection vulnerabilities on network appliances have been used to obtain persistent access and exfiltrate data. Organizations should assume that successful exploitation could result in a breach and review authentication logs and data flows for anomalies. You can run a free exposure scan of your email addresses against known breach data to check for prior incidents involving your domains.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedArray Networks · ArrayOS AG
WeaknessCWE-78
Added to CISA KEVDec 8, 2025
Federal patch deadlineDec 29, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities