CVE-2020-15069: Sophos XG Firewall Buffer Overflow Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-02-06. EPSS: 10.7% chance of exploitation in the next 30 days.

Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.

Affected products

  • Sophos XG Firewall Firmware: from 17.0, before 17.5 (fixed in 17.5); version 17.5 only

Published 2020-06-29. Last modified 2026-06-17.