Sophos Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Sophos products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

8

In CISA KEV

7

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

Sophos KEVs Added by Year

Loading...

8 Sophos KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2022-3980

An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed...

High Not in CISA 09 Nov 2025
CVE-2020-12271

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in...

Confirmed In CISA 03 Nov 2021
CVE-2020-25223

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

Confirmed In CISA 25 Mar 2022
CVE-2022-1040

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5...

Confirmed In CISA 31 Mar 2022
CVE-2022-3236

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and...

Confirmed In CISA 23 Sep 2022
CVE-2023-1671

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of...

Confirmed In CISA 16 Nov 2023
CVE-2020-29574

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL...

Confirmed In CISA 06 Feb 2025
CVE-2020-15069

Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless...

Confirmed In CISA 06 Feb 2025

Common Vulnerability Classes (CWE)

  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 2
  • CWE-120 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') 1
  • CWE-611 — Improper Restriction of XML External Entity Reference 1
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology