CVE-2022-1040

Sophos Firewall

Published 25 Mar 2022 · updated 17 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 31 Mar 2022, with a remediation deadline of 21 Apr 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

References