CVE-2020-11503: Sophos SFOS

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.

Affected products

  • Sophos SFOS: before 17.5 (fixed in 17.5); version 17.5 only

Published 2020-06-18. Last modified 2026-06-17.