A command injection vulnerability affecting Array Networks AG Series secure access gateways has been actively exploited since at least August 2025. The flaw, which resides in the DesktopDirect remote desktop access feature, allows attackers to execute arbitrary commands on vulnerable devices. JPCERT/CC confirmed that threat actors have leveraged this vulnerability to deploy web shells and create rogue users, with attacks traced to the IP address 194.233.100[.]138. The vulnerability impacts ArrayOS versions 9.4.5.8 and earlier, and was remediated in version 9.4.5.9 released in May 2025. Organizations unable to immediately patch are advised to disable DesktopDirect services and implement URL filtering to block URLs containing a semicolon.
The attacks have primarily targeted organizations in Japan, but scans indicate that over 1,800 ArrayAG instances are exposed globally, with concentrations in China, Japan, and the United States. The lack of a CVE identifier for this vulnerability complicates tracking and patch management. While a previous authentication bypass flaw in the same product was linked to the MirrorFace threat group, there is currently no evidence connecting the latest exploitation activity to any known actor. Enterprises using AG Series gateways are urged to update to the latest firmware and review their exposure, especially if the DesktopDirect feature is enabled.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Security researchers reported that over 1,800 internet-exposed Array AG devices were potentially vulnerable worldwide, with most located in Asia. The finding highlighted the continued exposure of unpatched systems despite the availability of a fix since May.
JPCERT/CC reported that the Array AG gateway command injection flaw had been actively exploited since August 2025, with activity traced to IP address 194.233.100[.]138. It urged organizations to patch, preserve logs before updating, and use temporary mitigations such as disabling DesktopDirect and filtering malicious URL patterns if patching was not immediately possible.
Threat actors started exploiting the command injection flaw against unpatched Array Networks AG Series gateways in Japan. The attacks involved arbitrary command execution and post-compromise activity such as webshell deployment and unauthorized user creation.
Array Networks released a fix for a command injection vulnerability in the DesktopDirect feature of AG Series secure access gateways with ArrayOS version 9.4.5.9. The flaw affected ArrayOS AG 9.4.5.8 and earlier and did not receive a public CVE identifier.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcethecyberexpress.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.