{"record":"Sophos evidence record","url":"https://nexalign.io/vendors/sophos","vendor":{"slug":"sophos","name":"Sophos","domain":"sophos.com","category":"endpoint-security","categoryLabel":"Endpoint security (EDR and XDR)"},"lastChecked":"2026-07-30T10:17:50.154Z","coverage":{"earliest":"2020-04-27T04:00:01.000Z","latest":"2026-07-16T04:17:49.201Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":58,"kindsOfSource":7,"attributedAdvisories":38,"knownExploited":6,"registerEntriesNotAttributable":0,"practitionerThreads":5,"independentItems":2,"vendorPublishedItems":1,"shareFromSourcesTheVendorDoesNotControl":0.93},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":25,"latest":"2025-09-09T20:58:26.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":13,"latest":"2025-07-22T09:46:51.430Z"},{"source":"Known Exploited Vulnerabilities catalogue","operator":"CISA, United States","classification":"authoritative","items":6,"latest":"2025-02-06T00:00:00.000Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":5,"latest":"2024-12-11T23:17:34.000Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":3,"latest":"2026-04-07T04:13:19.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":2,"latest":"2026-07-16T04:17:49.201Z"},{"source":"The vendor's own documentation","operator":"Vendor website, indexed by nexalign","classification":"vendor-controlled","items":4,"latest":"2026-07-01T16:47:10.476Z"}],"advisories":{"shown":6,"total":38,"truncated":true,"fullList":"https://nexalign.io/vendors/sophos/advisories","items":[{"id":"CVE-2020-15069","description":"Sophos XG Firewall Buffer Overflow Vulnerability","severity":"critical","cvss":9.8,"knownExploited":true,"date":"2025-02-06T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2020-15069","https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-7197"]},{"id":"CVE-2023-1671","description":"Sophos Web Appliance Command Injection Vulnerability","severity":"critical","cvss":9.8,"knownExploited":true,"date":"2023-11-16T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2023-1671","https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-23899"]},{"id":"CVE-2022-3236","description":"Sophos Firewall Code Injection Vulnerability","severity":"critical","cvss":9.8,"knownExploited":true,"date":"2022-09-23T12:50:13.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42644","https://nvd.nist.gov/vuln/detail/CVE-2022-3236"]},{"id":"CVE-2022-1040","description":"Sophos Firewall Authentication Bypass Vulnerability","severity":"critical","cvss":9.8,"knownExploited":true,"date":"2022-03-31T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2022-1040","https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24387"]},{"id":"CVE-2020-25223","description":"Sophos SG UTM Remote Code Execution Vulnerability","severity":"critical","cvss":9.8,"knownExploited":true,"date":"2022-03-25T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2020-25223","https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-17913"]},{"id":"CVE-2020-12271","description":"Sophos SFOS SQL Injection Vulnerability","severity":"critical","cvss":10,"knownExploited":true,"date":"2021-11-03T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2020-12271","https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-4584"]}]},"practitionerThreads":{"shown":5,"total":5,"truncated":false,"items":[{"title":"I’m Ross McKerchar, CISO at Sophos: AMA on tackling the issue of detecting fraudulent remote IT hires and building workable controls.","context":"r/cybersecurity","url":"https://www.reddit.com/r/cybersecurity/comments/1qwmswn/im_ross_mckerchar_ciso_at_sophos_ama_on_tackling/","date":"2026-02-05T14:31:49.000Z"},{"title":"US names Chinese national it alleges was behind 2020 attack on Sophos firewalls","context":"Hacker News","url":"https://news.ycombinator.com/item?id=42394166","date":"2024-12-11T23:17:34.000Z"},{"title":"Sophos has installed monitoring software on its customers' systems for years","context":"Hacker News","url":"https://news.ycombinator.com/item?id=42114866","date":"2024-11-12T12:03:49.000Z"},{"title":"Sophos' 5-Year War with the Chinese Hackers Hijacking Its Devices","context":"Hacker News","url":"https://news.ycombinator.com/item?id=42022786","date":"2024-11-01T23:54:42.000Z"},{"title":"Sophos' 5-Year War with the Chinese Hackers Hijacking Its Devices","context":"Hacker News","url":"https://news.ycombinator.com/item?id=42007947","date":"2024-10-31T15:36:17.000Z"}]},"independentCoverage":{"shown":2,"total":2,"truncated":false,"items":[{"title":"Sophos - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Sophos","date":null},{"title":"Sophos Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/endpoint-protection-platforms/vendor/sophos","date":null}]},"vendorPublished":{"shown":1,"total":1,"truncated":false,"items":[{"title":"Sophos: Schutz gegen Cyberangriffe mit Cybersecurity as a Service","url":"https://www.sophos.com/de-de","date":"2026-07-01T16:47:10.476Z"}]},"openQuestions":["Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}