Find notable cyber news and cases, enriched with sources, timelines, and signals.

ArrayOS 9.4.5.9 security update for command injection

Security Patch Release
First reported
Last updated
Happening score
H score 50
1 unique sources, 1 articles

Summary

Hide ▲

Array Networks issued ArrayOS 9.4.5.9 to fix a command injection issue affecting ArrayOS 9.4.5.8 and earlier, closing a path to arbitrary command execution on exposed AG Series secure access gateways. The fix applies to systems where DesktopDirect is enabled, which is the feature tied to the exposed remote-access surface. Operators that cannot patch immediately are advised to disable DesktopDirect and use URL filtering as a temporary safeguard.

Related Happenings

Array AG Series VPN exploitation wave targeting Japan

Exploitation Wave
H score6 First: 05.12.2025 01:05 Last: 05.12.2025 01:05 Sources 1

About this happening: Array AG Series VPN devices are seeing active exploitation against organizations in Japan, with abuse observed since at least August. Attackers are using a comma...

Timeline

  1. 05.12.2025 07:40 2 articles · 7mo ago

    ArrayOS 9.4.5.9 security update for command injection

    Initial Disclosure

    On May 11, 2025, Array Networks addressed a command injection flaw in ArrayOS by releasing 9.4.5.9 for AG Series secure access gateways. The fix covered ArrayOS 9.4.5.8 and earlier and targeted the DesktopDirect exposure path.

    Show sources