CVE-2022-3696: Sophos XG Firewall Firmware
High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
Affected products
- Sophos XG Firewall Firmware: up to and including 19.0
Published 2022-12-01. Last modified 2026-06-17.