Sophos known exploited vulnerabilities
CISA lists 7 Sophos CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2025-02-06), and 2 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2023-1671 (Web Appliance): EPSS 100.0%, added 2023-11-16
- CVE-2022-1040 (Firewall): EPSS 99.8%, added 2022-03-31
- CVE-2022-3236 (Firewall): EPSS 98.9%, added 2022-09-23
- CVE-2020-25223 (SG UTM): EPSS 96.8%, added 2022-03-25
- CVE-2020-12271 (SFOS): EPSS 42.4%, added 2021-11-03
Most affected Sophos products
Firewall (2), CyberoamOS (1), XG Firewall (1), Web Appliance (1), SG UTM (1), SFOS (1).
All Sophos CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2020-29574 | CyberoamOS | CyberoamOS (CROS) SQL Injection | 2025-02-06 | 2025-02-27 | 4.7% | Yes |
| CVE-2020-15069 | XG Firewall | XG Firewall Buffer Overflow | 2025-02-06 | 2025-02-27 | 10.7% | – |
| CVE-2023-1671 | Web Appliance | Web Appliance Command Injection | 2023-11-16 | 2023-12-07 | 100.0% | – |
| CVE-2022-3236 | Firewall | Firewall Code Injection | 2022-09-23 | 2022-10-14 | 98.9% | – |
| CVE-2022-1040 | Firewall | Firewall Authentication Bypass | 2022-03-31 | 2022-04-21 | 99.8% | – |
| CVE-2020-25223 | SG UTM | SG UTM Remote Code Execution | 2022-03-25 | 2022-04-15 | 96.8% | – |
| CVE-2020-12271 | SFOS | SFOS SQL Injection | 2021-11-03 | 2022-05-03 | 42.4% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors