CVE-2025-66644: Array Networks ArrayOS AG OS Command Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-12-08. EPSS: 3.4% chance of exploitation in the next 30 days.

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

Affected products

Published 2025-12-05. Last modified 2026-06-17.