← Vulnerability feed

Vulnerability record · CVE-2022-1040 · published 25 March 2022

CVE-2022-1040: Sophos Firewall auth bypass in User Portal and Webadmin leads to RCE

Sophos · Sfos

Sophos Firewall v18.5 MR3 and older contain an authentication bypass in the User Portal and Webadmin that lets a remote attacker execute code. The flaw is remotely reachable without credentials or user interaction, and public exploit code exists, making it a serious perimeter risk.

9.8 CVSS 3.1 Critical CISA KEV since 31 Mar 2022 EPSS 100% · top 0.1%
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution on an internet-facing security device, with public exploits and KEV listing, warrants immediate patching.

What it is

Sophos Firewall v18.5 MR3 and older contain an authentication bypass in the User Portal and Webadmin that lets a remote attacker execute code. The flaw is remotely reachable without credentials or user interaction, and public exploit code exists, making it a serious perimeter risk.

Impact

An unauthenticated attacker can bypass authentication and execute arbitrary code on the firewall, gaining full control of the device and its traffic-handling position.

Attack surface

Reachable over the network via the User Portal and Webadmin interfaces; the CVSS vector shows no privileges required and no user interaction.

Exploitation

Listed in CISA KEV since 2022-03-31 with a 30-day EPSS probability near 0.998, and references include Exploit-tagged entries on Packet Storm and Exploit-DB.

What to do

  • Apply the Sophos vendor update for SFOS per advisory sophos-sa-20220325-sfos-rce; upgrade beyond v18.5 MR3.
  • Restrict network access to the User Portal and Webadmin to trusted management networks only.
  • Disable or block external exposure of the User Portal and Webadmin where not required.
  • Review firewall configuration and logs for unauthorized changes after patching.
  • Monitor vendor advisory and CISA KEV guidance for any follow-up actions.

Detection

  • Hunt firewall and web logs for anomalous requests to User Portal and Webadmin endpoints from untrusted sources.
  • Alert on unexpected administrative logins, new admin accounts, or configuration changes on Sophos Firewall.
  • Monitor for outbound connections or process activity on the firewall consistent with post-exploitation.
  • Correlate network telemetry for scanning or exploitation attempts against the management interfaces.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-1040 to the Known Exploited Vulnerabilities catalog on 31 March 2022 as "Sophos Firewall Authentication Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 21 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-1040 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-12271Sophos XG Firewall SFOS SQL Injection Leading to RCESophos XG Firewall devices running SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 contain a SQL injection flaw in the administration (HTTPS) servi…KEVEPSS 42%analysed9.8CVE-2020-11503Sophos sfos out-of-bounds write vulnerabilityA heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary …EPSS 1.4%8.8CVE-2018-16117Sophos sfos os command injection vulnerabilityA shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to exec…EPSS 44%8.8CVE-2018-16116Sophos sfos sql injection vulnerabilitySQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute ar…EPSS 1.9%8.1CVE-2018-16118Sophos sfos os command injection vulnerabilityA shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attacker…EPSS 3.7%6.1CVE-2017-18014Sophos sfos cross-site scripting vulnerabilityAn NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a pe…EPSS 2.3%5.3CVE-2022-0331Sophos sfos vulnerabilityAn information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall ver…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2022-1040), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.