A command injection in Array Networks AG Series secure access gateways has been actively exploited since August 2025, according to an advisory issued this week by JPCERT/CC.

The vulnerability, which does not yet have a CVE identifier, was patched by the company on May 11, 2025. It is found in Array's DesktopDirect , a remote desktop access solution that allows users to securely access their work computers from any location
See also: Splunk Enterprise vulnerability allows privilege escalation
“ Exploitation of this vulnerability could allow attackers to execute arbitrary commands ,” JPCERT/CC said . “ This vulnerability affects systems where the ‘DesktopDirect’ feature, which provides remote desktop access, is enabled .”
The agency confirmed incidents in Japan that exploited the vulnerability after August 2025 to install web shells on vulnerable devices. The attacks originated from the IP address “194.233.100[.]138”.
See also: Sneeit Framework: Hackers exploit vulnerability in WordPress plugin

Array Networks AG Series Vulnerability: No Attack Details
There are currently no details available on the scale of the attacks, the exploit of the vulnerability, or the identity of the threat actors exploiting it. However, an authentication bypass vulnerability in the same product (CVE-2023-28461, 9.8) was exploited last year by a China-linked group cyberespionage known as MirrorFace . The group has a history of targeting Japanese organizations since 2019.
There is no evidence to suggest that the threat actor could be linked to the latest series of attacks. The vulnerability affects ArrayOS versions 9.4.5.8 and earlier and has been addressed in ArrayOS version 9.4.5.9. Users are urged to apply the latest updates as soon as possible to mitigate potential threats.
See also: Critical vulnerabilities in React and Next.js allow RCE attacks

If fixing is not an immediate option, it is recommended to disable DesktopDirect services and use URL filtering to deny access to URLs containing semicolons.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
