Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sophos Limited

First CVE: Feb 12, 2004Active for: 22 yearsTotal CVEs: 169
56.7
VTI Score
TOP TARGET

Sophos Limited maintains a moderately broad portfolio of endpoint protection, network security, and web-filtering products that span enterprise and small-business deployments, positioning its vulnerabilities in frequently targeted defensive infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit tooling, reflecting the security-critical nature of these products and their high visibility to attackers. The exposure recurs across core products including Sophos Anti-Virus, web appliances, and the XG Firewall line, and concentrates in weakness classes spanning input handling, memory safety, and command-injection vectors that are characteristic of large network and endpoint control software. Defenders should prioritize patches for internet-exposed appliances and endpoint infrastructure and track coordinated advisory releases. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
169
Total CVEs
More Total CVEs than 100% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
4.1%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Sophos Limited over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2004
22 years ago
Most Recent CVE
Jul 21, 2025
368 days ago

Self-Reporting Analysis

Of all the CVEs published by Sophos Limited as a CNA, 87.5% affect products that Sophos Limited develops as a vendor.

87.5%
12.5%
Self-reported: 42 (87.5%)
Third-party: 6 (12.5%)

Of all the CVEs published that affect products developed by Sophos Limited, 24.9% are self-published by Sophos Limited as a CNA.

24.9%
75.1%
Self-published: 42 (24.9%)
Other CNAs: 127 (75.1%)

Products(73 total)

Top CVEs

Signals from CVEs in this vendor scope (169 CVEs).

169 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-1671CRITICAL
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
Apr 4, 20239.898YESYES
CVE-2022-3236CRITICAL
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
Sep 23, 20229.898YESYES
CVE-2022-1040CRITICAL
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
Mar 25, 20229.898YESYES
CVE-2020-25223CRITICAL
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
Sep 25, 20209.898YESYES
CVE-2020-12271CRITICAL
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices co
Apr 27, 20209.887YESNO
CVE-2013-4983HIGH
The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to execute arbitrary commands via shell me
Sep 10, 201310.086NOYES
CVE-2015-7547HIGH
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attac
Feb 18, 20168.183NOYES
CVE-2020-15069CRITICAL
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was publishe
Jun 29, 20209.872YESNO
CVE-2014-2849HIGH
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.
Apr 11, 20148.572NOYES
CVE-2020-29574CRITICAL
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
Dec 11, 20209.871YESNO
View all 169 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products169 CVEs
46%
42%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local31 (18.3%)
Network65 (38.5%)
Unknown68 (40.2%)
Physical2 (1.2%)
Adjacent Network3 (1.8%)
Attack Complexity
Low92 (54.4%)
High9 (5.3%)
Unknown68 (40.2%)
User Interaction
None82 (48.5%)
Unknown68 (40.2%)
Required19 (11.2%)
Privileges Required
Low33 (19.5%)
High23 (13.6%)
None45 (26.6%)
Unknown68 (40.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (169 CVEs).

CISA KEV
7 CVEs
4.1% of CVEs· 99th percentile
Metasploit
6 CVEs
3.6% of CVEs· 98th percentile
Nuclei
5 CVEs
3.0% of CVEs· 95th percentile
ExploitDB
32 CVEs
18.9% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sophos Limited.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sophos Limited — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sophos Limited's Products

View all 5 CNAs →

Top CWEs