Sophos Limited maintains a moderately broad portfolio of endpoint protection, network security, and web-filtering products that span enterprise and small-business deployments, positioning its vulnerabilities in frequently targeted defensive infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit tooling, reflecting the security-critical nature of these products and their high visibility to attackers. The exposure recurs across core products including Sophos Anti-Virus, web appliances, and the XG Firewall line, and concentrates in weakness classes spanning input handling, memory safety, and command-injection vectors that are characteristic of large network and endpoint control software. Defenders should prioritize patches for internet-exposed appliances and endpoint infrastructure and track coordinated advisory releases. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sophos Limited over time
Of all the CVEs published by Sophos Limited as a CNA, 87.5% affect products that Sophos Limited develops as a vendor.
Of all the CVEs published that affect products developed by Sophos Limited, 24.9% are self-published by Sophos Limited as a CNA.
Signals from CVEs in this vendor scope (169 CVEs).
169 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1671CRITICAL A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code. | Apr 4, 2023 | 9.8 | 98 | YES | YES |
CVE-2022-3236CRITICAL A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older. | Sep 23, 2022 | 9.8 | 98 | YES | YES |
CVE-2022-1040CRITICAL An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older. | Mar 25, 2022 | 9.8 | 98 | YES | YES |
CVE-2020-25223CRITICAL A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11 | Sep 25, 2020 | 9.8 | 98 | YES | YES |
CVE-2020-12271CRITICAL A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices co | Apr 27, 2020 | 9.8 | 87 | YES | NO |
CVE-2013-4983HIGH The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to execute arbitrary commands via shell me | Sep 10, 2013 | 10.0 | 86 | NO | YES |
CVE-2015-7547HIGH Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attac | Feb 18, 2016 | 8.1 | 83 | NO | YES |
CVE-2020-15069CRITICAL Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was publishe | Jun 29, 2020 | 9.8 | 72 | YES | NO |
CVE-2014-2849HIGH The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request. | Apr 11, 2014 | 8.5 | 72 | NO | YES |
CVE-2020-29574CRITICAL An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely. | Dec 11, 2020 | 9.8 | 71 | YES | NO |
Signals from CVEs in this vendor scope (169 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sophos Limited.
Media articles that mention a CVE ID that affects a product developed by Sophos Limited — matched by CVE ID, not by vendor name.