FAIL › dossier
Firewall
PRODUCT· dossier confidence 60%
Sophos is a public UK-based cybersecurity firm with over 3,000 employees, but its firewall product line has demonstrated a pattern of high-severity remote code execution vulnerabilities in management interfaces, requiring close monitoring for DIB/CMMC compliance.
PROFILE
CategoryCybersecurityWhat they doSophos is a cybersecurity company that provides endpoint security, network security, and cloud security solutions.Size3k+ employeesOwnershippublic
Websitehttps://sophos.com ↗
SECURITY POSTURE
Sophos has a mixed security posture with a history of high-severity remote code execution vulnerabilities in its firewall products, indicating potential gaps in secure development lifecycle practices for edge and network security appliances.
Notable failures
- CVE-2022-1040: Authentication bypass RCE in User Portal/Webadmin
- CVE-2022-3236: RCE in User Portal/Webadmin
- CVE-2022-1040: High-severity RCE in firewall authentication bypass
Patterns: repeated unpatched RCE in firewall management interfaces; authentication bypass leading to remote code execution
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-31 | CVE-2022-1040 | high | Sophos Firewall's User Portal and Webadmin suffered an authentication bypass vulnerability enabling remote code execution. |
| 2022-09-23 | CVE-2022-3236 | high | Sophos Firewall exposed to remote code execution through User Portal and Webadmin. |
DOSSIER SOURCES
- Sophos - Overview, News & Similar companies | ZoomInfo.com · www.zoominfo.com
- Sophos Group plc (SOPH.L) (SOPH) Share Price, News & Analysis · www.marketbeat.com
- Sophos Careers | Remote, Hybrid | 191 Open Positions | August 2026 · jobera.com
Open questions: What is the exact employee count of Sophos? · What is the precise founding year of Sophos?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-14 03:48:44.795106+00:00