Sophos Firewall found a serious security issue


Sophos Firewall carries a high-severity vulnerability that’s being actively exploited in the wild, the company has confirmed, urging system admins to apply the patch, or the workaround, as quickly as possible.
In an official announcement, the company said that the threat actor abusing the flaw focuses on a specific type of companies for its victims.
“Sophos has observed this vulnerability being used to target a small set of specific organizations, primarily in the South Asia region,” Sophos said. “We have informed each of these organizations directly. Sophos will provide further details as we continue to investigate.”
Remote code execution
The vulnerability was discovered in the User Portal and Webadmin. Tracked as CVE-2022-3236, the flaw allows threat actors to remotely execute code. The company has already released a fix, that should be applied automatically to most users. By default, the feature of automatic updates is enabled, so unless system admins deliberately turned it off, they should be fine.
Those that should pay extra care are those that have the feature turned off, or those who are using older versions of Sophos Firewall. These would need to upgrade the software, first.
System admins that are unable to apply the patch at this time can also use the workaround – making sure the User Portal and Webadmin aren’t exposed to WAN.
“Disable WAN access to the User Portal and Webadmin by following device access best practices and instead use VPN and/or Sophos Central (preferred) for remote access and management,” Sophos said.
This is at least the third time this year Sophos Firewall made headlines for all the wrong reasons. In April this year, the company announced patching a flaw that allowed threat actors to remotely execute any code, including viruses and malware, on an endpoint (opens in new tab) running its firewall software, and in late June, it fixed CVE-2022-1040 (authentication bypass flaw that allows arbitrary code execution).
Via: BleepingComputer (opens in new tab)
Audio player loading… Sophos Firewall carries a high-severity vulnerability that’s being actively exploited in the wild, the company has confirmed, urging system admins to apply the patch, or the workaround, as quickly as possible. In an official announcement, the company said that the threat actor abusing the flaw focuses on…
Recent Posts
- The Oppo Find N5 has made me even more excited for the Samsung Galaxy S25 Edge – here’s why
- Apple Intelligence is coming to the Vision Pro
- Security flaw in popular stalkerware apps is exposing phone data of millions
- Anker’s 58-liter solar fridge is a noisy power-monster
- Salt Typhoon hackers used this clever technique to attack US networks
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010