Sophos firewalls require an URGENT new flame shield.

Share This Post

Sophos recently announced that it has released a hotfix for an urgent flaw in its firewalls. Tracked as CVE-2022-1040, the vulnerability allows attackers to bypass user authentication via the firewall’s User Portal or WebAdmin interface, and then execute arbitrary code. The flaw has been assigned a severity rating of 9.8 out of 10.

Sophos declared that it “has observed this vulnerability being used to target a small set of specific organizations, primarily in the South Asia region.” Now that the flaw has been widely publicized, expect that list of targets to expand.

The vendor’s hotfix should be automatically applied to all vulnerable devices that have the “Allow automatic installation of hotfixes” feature enabled, which it is by default. However, organizations that have disabled the feature or are running End Of Life hardware will need to manually upgrade in order to patch the security hole.

You can verify if the hotfix for CVE-2022-1040 has been applied to your Sophos firewall by following the directions laid out here: https://support.sophos.com/support/s/article/KB-000043853?language=en_US



Reach out to our incident response team for help

More To Explore

Information Security News 3-9-2026

Experts Warn Iran-Linked Hacktivists Could Target Governments Article Link: https://www.nextgov.com/cybersecurity/2026/03/iran-linked-hacktivists-could-target-governments-experts-warn/411876/ Iran-Linked MuddyWater Hackers Target U.S. Networks with New Dindoor Backdoor Article Link: https://thehackernews.com/2026/03/iran-linked-muddywater-hackers-target.html Indian APT

Information Security News – 3/2/2026

CrowdStrike: Average Cyberattack Breakout Time Now Under 30 Minutes Article Link: https://www.scworld.com/news/crowdstrike-average-cyberattack-breakout-time-now-under-30-minutes Critical Cisco SD-WAN Bug Exploited in Zero-day Attacks Since 2023 Article Link: https://www.bleepingcomputer.com/news/security/critical-cisco-sd-wan-bug-exploited-in-zero-day-attacks-since-2023/

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.