logo

CVE-2022-3236: Official Patch Out Now

ID: 2e975f5c-9c50-507a-9ea6-36360d2f7cc4

STIX ID: report--2e975f5c-9c50-507a-9ea6-36360d2f7cc4

Feed Name: Arctic Wolf Blog

Threat Score
75/100

Date Published: 2022-12-12

Date Updated: 2026-04-27

...
...

Sophos Firewall is affected by a critical code injection vulnerability (CVE-2022-3236) allowing remote code execution if Webadmin/User Portal have WAN access; public proof-of-concept code was briefly available and Sophos has observed limited active exploitation in South Asia. Arctic Wolf and Sophos strongly recommend applying the v19.5 GA patch and disabling WAN access (use VPN or Sophos Central) to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.