Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-18367
Local Privilege Escalation in Sophos Endpoint and Home for macOS Allows Arbitrary Code Execution as Root
CVE-2025-10159
An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7).
CVE-2009-10005
ContentKeeper Web Appliance < 125.10 Arbitrary File Access via mimencode
CVE-2024-13973
A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.
CVE-2024-13974
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.
