CVE-2019-17059: Sophos CyberoamOS

Critical severity, CVSS 9.8. EPSS: 7.4% chance of exploitation in the next 30 days.

A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitrary commands via the Web Admin and SSL VPN consoles.

Affected products

  • Sophos CyberoamOS: before 10.6.6 (fixed in 10.6.6); version 10.6.6 only

Published 2019-10-11. Last modified 2026-06-17.