CVE-2019-17059: Sophos CyberoamOS
Critical severity, CVSS 9.8. EPSS: 7.4% chance of exploitation in the next 30 days.
A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitrary commands via the Web Admin and SSL VPN consoles.
Affected products
- Sophos CyberoamOS: before 10.6.6 (fixed in 10.6.6); version 10.6.6 only
Published 2019-10-11. Last modified 2026-06-17.