FAIL › dossier
Sophos
VENDOR· dossier confidence 20%
Sophos is a cybersecurity vendor with a concerning history of critical and high-severity remote code execution vulnerabilities in its firewall and web appliance products, particularly in management interfaces. The company has demonstrated recurring issues with input validation and authentication bypasses across multiple product lines.
PROFILE
Categorycybersecurity vendorWhat they doSophos provides cybersecurity solutions including firewalls, antivirus, and endpoint protection for organizations.
Websitehttps://www.sophos.com ↗
SECURITY POSTURE
Sophos has a poor security track record with multiple high and critical remote code execution vulnerabilities across its firewall and web appliance products between 2020 and 2022, indicating systemic issues in input validation and authentication bypasses.
Notable failures
- CVE-2020-12271 critical RCE in SFOS via SQL injection
- CVE-2020-29574 high RCE in CyberoamOS via SQL injection
- CVE-2020-15069 high RCE in XG Firewall via buffer overflow
- CVE-2023-1671 high RCE in Web Appliance via command injection
- CVE-2022-3236 high RCE in Firewall via code injection
- CVE-2022-1040 high auth bypass in Firewall User Portal
Patterns: repeated unpatched RCE vulnerabilities in web management interfaces; SQL injection and command injection in admin portals; authentication bypasses leading to RCE in user-facing portals
FAILURE HISTORY · 8
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-25 | CVE-2020-25223 | high | Sophos SG UTM WebAdmin had a remote code execution vulnerability that was actively exploited in the wild. |
| 2022-03-31 | CVE-2022-1040 | high | Sophos Firewall's User Portal and Webadmin suffered an authentication bypass vulnerability enabling remote code execution. |
| 2025-02-06 | CVE-2020-15069 | high | Sophos XG Firewalls were vulnerable to remote code execution via a bookmark feature, actively exploited in the wild. |
| 2025-02-06 | CVE-2020-29574 | high | Sophos's CyberoamOS had a remotely exploitable SQL injection vulnerability allowing unauthorized SQL execution without authentication. |
| 2023-11-16 | CVE-2023-1671 | high | Sophos Web Appliance Command Injection Vulnerability |
| 2022-09-23 | CVE-2022-3236 | high | Sophos Firewall exposed to remote code execution through User Portal and Webadmin. |
| 2021-11-03 | CVE-2020-12271 | critical | Sophos firewalls were vulnerable to SQL injection, potentially allowing attackers to steal credentials and execute code remotely. |
| 2020-12-11 | CVE-2020-29574 | critical | CVE-2020-29574: An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Vulnerability allows remote code execution and credential exfiltration when exposed on WAN, indicating a critical flaw in Sophos SFOS firmware.
synthesissevere-fallout-0.60
Unauthenticated SQL injection in Cyberoam OS WebAdmin represents a critical failure in vendor security posture, allowing remote arbitrary SQL execution without authentication, indicating severe neglig
Neutral CISA KEV catalog listing; no vendor-specific sentiment expressed.
Critical SQL injection flaw enabling remote code execution and credential theft when admin/portal services are exposed on WAN.
"Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords"
Neutral CVE database listing; no vendor-specific sentiment expressed.
Neutral threat intelligence site; no vendor-specific sentiment expressed.
Neutral CVE database listing; no vendor-specific sentiment expressed.
Neutral vulnerability reference site; no vendor-specific sentiment expressed.
Neutral security news site; no vendor-specific sentiment expressed.
Neutral coverage; no specific commentary on vendor handling or impact beyond listing CVE metadata.
Irrelevant; no mention of Cyberoam, CVE-2020-29574, or vendor response.
Irrelevant; discusses SK Telecom breach unrelated to Cyberoam or this CVE.
Irrelevant; discusses CISA KEV catalog without specific vendor commentary on Cyberoam.
Irrelevant; discusses Roundcube webmail RCE unrelated to Cyberoam or this CVE.
Irrelevant; discusses unrelated legal case with no security vendor commentary.
Severe vulnerability in Cyberoam OS WebAdmin allows unauthenticated remote SQL injection, exposing systems to arbitrary data manipulation and potential full compromise.
"An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely."
DOSSIER SOURCES
- Sophos Unveils AI-Native Cybersecurity Defense System Fusion · briefglance.com
- Sophos Home Review 2026: Is the Multi-Device Antivirus Worth It? · bestguide.com
- Sophos Careers | Remote, Hybrid, Onsite | 144 Open Positions | July 2026 · jobera.com
- Sophos News - The Sophos Blog · www.sophos.com
- Latest Cybersecurity Vulnerabilities | Real-Time CVE Database · cve.akaoma.com
- Sophos Firewall: v22.0 MR2: Feedback and experiences · community.sophos.com
Open questions: Sophos's current patching SLA for critical RCE vulnerabilities · Whether recent AI-native products inherit the same injection vulnerabilities as legacy products
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-17 04:33:16.506001+00:00