Sophos vendor intelligence

Sophos Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Sophos products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse Sophos KEVs Full KEV feed
Total KEVs
8
Known exploited vulnerabilities affecting Sophos products
In CISA KEV
7
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
Sophos KEVs with sensor-observed exploitation activity

The catalog gap matters for Sophos exposure

One of the eight exploited Sophos CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 12% of this vendor portfolio.

88%
Covered by CISA
12%
Beyond CISA
6
Product families

Attested Sophos CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2022-3980

An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed...

Sophos Mobile managed on-premises High Beyond CISA 09 Nov 2025
CVE-2020-12271

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in...

XG Firewall Confirmed In CISA 03 Nov 2021
CVE-2020-25223

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

SG UTM Confirmed In CISA 25 Mar 2022
CVE-2022-1040

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5...

Sophos Firewall Confirmed In CISA 31 Mar 2022
CVE-2022-3236

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and...

Sophos Firewall Confirmed In CISA 23 Sep 2022
CVE-2023-1671

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of...

Sophos Web Appliance Confirmed In CISA 16 Nov 2023
CVE-2020-29574

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL...

Cyberoam OS Confirmed In CISA 06 Feb 2025
CVE-2020-15069

Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless...

XG Firewall Confirmed In CISA 06 Feb 2025

Showing 8 of 8 Sophos known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, buffer copy without checking size, and restriction account for four mapped occurrences across this Sophos KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.