CVE-2024-12727: Sophos Firewall Firmware
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode.
Affected products
- Sophos Firewall Firmware: before 21.0.1 (fixed in 21.0.1)
Published 2024-12-19. Last modified 2026-06-17.