Page 1 of 1

Critical Sophos Firewall Vulnerabilities Allow Pre-Auth Remote Code Execution

Posted: Wed Jul 23, 2025 4:50 pm
by Shane1145
Sophos has disclosed five independent security vulnerabilities affecting its Firewall products, with two critical vulnerabilities enabling attackers to achieve remote code execution without authentication.

The cybersecurity vendor published the advisory on July 21, 2025, detailing vulnerabilities that impact specific configurations of Sophos Firewall installations, though the affected device populations remain relatively small at less than 1% for most issues.

https://cyberpress.org/critical-sophos- ... abilities/