CyberMax
Home › Exploited CVEs

Sophos known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 7 Sophos CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2025-02-06), and 2 are known to be used in ransomware campaigns.

Sophos CVEs added to CISA KEV per year
2021: 1202112022: 3202232023: 1202312025: 220252

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Sophos products

Firewall (2), CyberoamOS (1), XG Firewall (1), Web Appliance (1), SG UTM (1), SFOS (1).

All Sophos CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2020-29574CyberoamOSCyberoamOS (CROS) SQL Injection2025-02-062025-02-274.7%Yes
CVE-2020-15069XG FirewallXG Firewall Buffer Overflow2025-02-062025-02-2710.7%–
CVE-2023-1671Web ApplianceWeb Appliance Command Injection2023-11-162023-12-07100.0%–
CVE-2022-3236FirewallFirewall Code Injection2022-09-232022-10-1498.9%–
CVE-2022-1040FirewallFirewall Authentication Bypass2022-03-312022-04-2199.8%–
CVE-2020-25223SG UTMSG UTM Remote Code Execution2022-03-252022-04-1596.8%–
CVE-2020-12271SFOSSFOS SQL Injection2021-11-032022-05-0342.4%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors