CVE-2020-25223: Sophos SG UTM Remote Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 96.8% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

Affected products

  • Sophos Unified Threat Management: before 9.511 (fixed in 9.511); from 9.600, before 9.607 (fixed in 9.607); from 9.700, before 9.705 (fixed in 9.705); version 9.511 only; version 9.607 only; version 9.705 only

Published 2020-09-25. Last modified 2026-06-17.