Endpoint security (EDR and XDR)
Sophos advisories: every record the registers tie to its products
In one line
38 advisories are attributed to Sophos products in this record, covering November 2021 to September 2025, and 6 of them appear in the CISA catalogue of known exploited vulnerabilities. A further 0 register entries mention Sophos without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.
Attributed
38
tied to a named product
Known exploited
6
in the CISA catalogue
Rated critical
14
by the register
Last checked
Jul 30, 2026
sources re-queried
Why this list is shorter than a CVE mirror
The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Sophos, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.
0 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.
38 of the 38 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.
The full list, most recently exploited and most recent first
Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.
- CVE-2020-15069criticalCVSS 9.8Known exploitedFeb 06, 2025
Sophos XG Firewall Buffer Overflow Vulnerability
- CVE-2023-1671criticalCVSS 9.8Known exploitedNov 16, 2023
Sophos Web Appliance Command Injection Vulnerability
- CVE-2022-3236criticalCVSS 9.8Known exploitedSep 23, 2022
Sophos Firewall Code Injection Vulnerability
- CVE-2022-1040criticalCVSS 9.8Known exploitedMar 31, 2022
Sophos Firewall Authentication Bypass Vulnerability
- CVE-2020-25223criticalCVSS 9.8Known exploitedMar 25, 2022
Sophos SG UTM Remote Code Execution Vulnerability
- CVE-2020-12271criticalCVSS 10.0Known exploitedNov 03, 2021
Sophos SFOS SQL Injection Vulnerability
- CVE-2025-10159criticalCVSS 9.8Sep 09, 2025
An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7).
- WID-SEC-2025-1615highCVSS 9.8Jul 22, 2025
Affected products: Sophos Firewall
- CVE-2024-13973mediumCVSS 6.8Jul 21, 2025
A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.
- CVE-2024-13974highCVSS 8.1Jul 21, 2025
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve…
- CVE-2025-7382highCVSS 8.8Jul 21, 2025
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability…
- CVE-2025-7624criticalCVSS 9.8Jul 21, 2025
An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, if a quarantining policy is…
- CVE-2025-6704criticalCVSS 9.8Jul 21, 2025
An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a…
- CVE-2025-7433highCVSS 8.8Jul 17, 2025
A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025.1 and older allows arbitrary code execution.
- CVE-2024-13972highCVSS 8.8Jul 17, 2025
A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024.3.2 can lead to a local user gaining SYSTEM level privileges during a…
- CVE-2025-7472highCVSS 7.5Jul 17, 2025
A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a local user gaining system level privileges, if the installer is run as…
- CVE-2024-13861highCVSS 7.8Apr 11, 2025
A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitrary code execution as root.
- WID-SEC-2025-0288criticalCVSS 9.8Feb 07, 2025
Affected products: Sophos XG Firewall
- WID-SEC-2024-3735highCVSS 9.8Dec 20, 2024
Affected products: Sophos Firewall
- WID-SEC-2024-0556mediumCVSS 7.5Dec 09, 2024
Affected products: Ubuntu Linux, Sophos Unified Threat Management (UTM) Software
- WID-SEC-2023-1886highCVSS 8.8Jun 27, 2024
Affected products: Ubuntu Linux, Sophos Unified Threat Management (UTM) Software
- WID-SEC-2023-2910mediumCVSS 5.9Nov 15, 2023
Affected products: Sophos Unified Threat Management (UTM) Software
- WID-SEC-2023-2703mediumCVSS 6.5Oct 18, 2023
Affected products: Sophos Firewall
- CVE-2022-48309mediumCVSS 4.3Mar 01, 2023
A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.
- WID-SEC-2022-2217highCVSS 9.8Dec 08, 2022
Affected products: Sophos Firewall
- CVE-2022-3713highCVSS 8.8Dec 01, 2022
A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.
- CVE-2022-3696highCVSS 7.2Dec 01, 2022
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
- CVE-2022-3710lowCVSS 2.7Dec 01, 2022
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than…
- CVE-2022-3711mediumCVSS 4.3Dec 01, 2022
A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5…
- CVE-2022-3709mediumCVSS 6.8Dec 01, 2022
A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.
- CVE-2022-3226highCVSS 7.2Dec 01, 2022
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.
- CVE-2022-3980criticalCVSS 9.8Nov 16, 2022
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.
- WID-SEC-2022-2041highCVSS 8.1Nov 15, 2022
Affected products: Sophos Unified Threat Management (UTM) Software
- WID-SEC-2022-1529criticalCVSS 9.8Sep 26, 2022
Affected products: Sophos Firewall
- WID-SEC-2022-1393mediumCVSS 6.7Sep 13, 2022
Affected products: Sophos Firewall
- WID-SEC-2022-1386criticalCVSS 10.0Sep 13, 2022
Affected products: Sophos Firewall
- WID-SEC-2022-1385criticalCVSS 10.0Sep 13, 2022
Affected products: Sophos Firewall
- CVE-2022-1807highCVSS 7.2Sep 07, 2022
Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.
Which registers contributed
| Register | Operated by | Entries | Latest |
|---|---|---|---|
| European Vulnerability Database | ENISA, European Union | 25 | Sep 09, 2025 |
| CERT-Bund security advisories | BSI, Federal Republic of Germany | 13 | Jul 22, 2025 |
| Known Exploited Vulnerabilities catalogue | CISA, United States | 6 | Feb 06, 2025 |
The entry counts here are the raw register totals for Sophos, before attribution. They are larger than the list above for exactly that reason.
Questions this page answers
How many vulnerabilities does Sophos have?
38 advisories in this record are tied by a register to a product of Sophos. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.
Are any Sophos vulnerabilities being actively exploited?
6 of the 38 records here appear in the CISA catalogue of known exploited vulnerabilities, which lists flaws with confirmed exploitation in the wild. They are shown first in the list above. Whether any of them affects your deployment depends on the versions and components you run.
Why does this page show fewer CVEs for Sophos than other sites?
Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 0 register entries name Sophos without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.
Where do the Sophos advisories on this page come from?
From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany); Known Exploited Vulnerabilities catalogue (CISA, United States). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.
Does a long advisory list mean Sophos is insecure?
No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.
A list of advisories is not a risk assessment
What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.
The full Sophos record, including sources and open questions
