Sophos Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Sophos products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
8
In CISA KEV
7
Beyond CISA KEV
1
Sensor Observed
0
Virtual Patch Available
0
Sophos KEVs Added by Year
8 Sophos KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-3980
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed... |
Sophos Mobile managed on-premises | High | Not in CISA | 09 Nov 2025 |
|
CVE-2020-12271
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in... |
XG Firewall | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-25223
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11 |
SG UTM | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2022-1040
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5... |
Sophos Firewall | Confirmed | In CISA | 31 Mar 2022 |
|
CVE-2022-3236
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and... |
Sophos Firewall | Confirmed | In CISA | 23 Sep 2022 |
|
CVE-2023-1671
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of... |
Sophos Web Appliance | Confirmed | In CISA | 16 Nov 2023 |
|
CVE-2020-29574
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL... |
Cyberoam OS | Confirmed | In CISA | 06 Feb 2025 |
|
CVE-2020-15069
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless... |
XG Firewall | Confirmed | In CISA | 06 Feb 2025 |
Common Vulnerability Classes (CWE)
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 2
- CWE-120 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') 1
- CWE-611 — Improper Restriction of XML External Entity Reference 1
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology