CVE-2022-3696: Sophos XG Firewall Firmware

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.

Affected products

  • Sophos XG Firewall Firmware: up to and including 19.0

Published 2022-12-01. Last modified 2026-06-17.