Vendor

Sophos

As of , 7 Sophos vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2020-25223.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2020-25223Remote Code ExecutionSophos SG UTMPatch this weekMetasploit module; EPSS 0.970.97
2CVE-2023-1671Command InjectionSophos Web AppliancePatch this weekEPSS 0.990.99
3CVE-2022-3236Code InjectionSophos FirewallPatch this weekEPSS 0.990.99
4CVE-2022-1040Authentication BypassSophos FirewallPatch this weekEPSS 0.990.99
5CVE-2020-12271SQL InjectionSophos SFOSPatch this weekRansomware use0.42
6CVE-2020-29574(CROS) SQL InjectionSophos CyberoamOSPatch this weekRansomware use0.05
7CVE-2020-15069Buffer OverflowSophos XG FirewallPatch soon0.11

Products

  • Firewall2 entries
  • CyberoamOS1 entry
  • SFOS1 entry
  • SG UTM1 entry
  • Web Appliance1 entry
  • XG Firewall1 entry

Added each year

1232021: 1120212022: 3320222023: 1120232024: nonenone20242025: 2220252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20211
20223
20231
2024none
20252
2026none

Used in ransomware

Changes CISA made to these entries

  1. CVE-2020-29574 Sophos CyberoamOSRansomware use: Unknown to Known.

Every change we recorded