CVE-2024-12729: Sophos Firewall Firmware
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).
Affected products
- Sophos Firewall Firmware: before 21.0.1 (fixed in 21.0.1)
Published 2024-12-19. Last modified 2026-06-17.