Sophos vendor intelligence
Sophos Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Sophos products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 8
- Known exploited vulnerabilities affecting Sophos products
- In CISA KEV
- 7
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Sophos KEVs with sensor-observed exploitation activity
The catalog gap matters for Sophos exposure
One of the eight exploited Sophos CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 12% of this vendor portfolio.
- 88%
- Covered by CISA
- 12%
- Beyond CISA
- 6
- Product families
Attested Sophos CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-3980
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed... |
Sophos Mobile managed on-premises | High | Beyond CISA | 09 Nov 2025 |
|
CVE-2020-12271
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in... |
XG Firewall | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-25223
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11 |
SG UTM | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2022-1040
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5... |
Sophos Firewall | Confirmed | In CISA | 31 Mar 2022 |
|
CVE-2022-3236
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and... |
Sophos Firewall | Confirmed | In CISA | 23 Sep 2022 |
|
CVE-2023-1671
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of... |
Sophos Web Appliance | Confirmed | In CISA | 16 Nov 2023 |
|
CVE-2020-29574
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL... |
Cyberoam OS | Confirmed | In CISA | 06 Feb 2025 |
|
CVE-2020-15069
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless... |
XG Firewall | Confirmed | In CISA | 06 Feb 2025 |
No Sophos CVEs match this search or filter.
Showing 8 of 8 Sophos known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, buffer copy without checking size, and restriction account for four mapped occurrences across this Sophos KEV portfolio.
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CWE-611
Improper Restriction of XML External Entity Reference
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-94
Improper Control of Generation of Code ('Code Injection')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.