Skip to content
COOEY

EXPOSURES › CVE-2025-66644

CVE-2025-66644

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-12-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-66644 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

ArrayOS AG OS Command Injection Vulnerability actively exploited

Array Networks' ArrayOS AG suffered an OS command injection flaw, allowing attackers to execute arbitrary commands.

Shame score — Active exploitation of a critical OS command injection vulnerability in a widely used product.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.