Array Networks Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Array Networks products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
2
In CISA KEV
2
Beyond CISA KEV
0
Sensor Observed
0
Virtual Patch Available
0
Array Networks KEVs Added by Year
Loading...
2 Array Networks KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-66644
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. |
ArrayOS AG | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2023-28461
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN... |
Array AG Series and vxAG | Confirmed | In CISA | 25 Nov 2024 |
Common Vulnerability Classes (CWE)
- CWE-306 — Missing Authentication for Critical Function 1
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology