Sophos Limited

First CVE: Mar 22, 2021Active for: 5 years
48
CVEs Published
More CVEs Published than 56% of tracked CNAs
9.6
Avg CVEs / Year
More Avg CVEs / Year than 52% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 70% of tracked CNAs
6.3%
In CISA KEV
Higher KEV Rate than 97% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Sophos Limited as a CNA, 87.5% affect products that Sophos Limited develops as a vendor.

87.5%
12.5%
Self-reported: 42Third-party: 6

Of all the CVEs published that affect products developed by Sophos Limited, 24.9% are self-published by Sophos Limited as a CNA.

24.9%
75.1%
Self-published: 42Published by other CNAs: 127

Trends Over Time

The number and severity of CVEs published by Sophos Limited over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 22, 2021
5 years ago
Most Recent CVE
Sep 9, 2025
318 days ago

Top CVEs

All CVEs published by Sophos Limited as a CNA, regardless of affected vendor or product.

48 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
Apr 4, 20239.898YESYES
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
Sep 23, 20229.898YESYES
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
Mar 25, 20229.898YESYES
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.
Nov 16, 20229.846NOYES
An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution
Jul 21, 20259.835NONO
An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (M
Sep 9, 20259.834NONO
An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, if a quarantining
Jul 21, 20259.834NONO
A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).
Dec 19, 20249.831NONO
A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead
Dec 19, 20249.831NONO
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to
Jul 21, 20258.128NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA48 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local13 (27.1%)
Network32 (66.7%)
Unknown0 (0.0%)
Physical1 (2.1%)
Adjacent Network2 (4.2%)
Attack Complexity
Low45 (93.8%)
High3 (6.3%)
Unknown0 (0.0%)
User Interaction
None38 (79.2%)
Unknown0 (0.0%)
Required10 (20.8%)
Privileges Required
Low14 (29.2%)
High16 (33.3%)
None18 (37.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (48 CVEs).

CISA KEV
3 CVEs
6.2% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
8.3% of CVEs· 95th percentile
ExploitDB
2 CVEs
4.2% of CVEs· 93rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Sophos Limited as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Sophos Limited as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs