>> All posts

CVE-2022-1040: Sophos Firewall authentication bypass to RCE, exploited in the wild

The short version: Sophos Firewall has an authentication-bypass flaw (CVE-2022-1040) in its User Portal and Webadmin interfaces that a remote attacker can use to bypass login and reach remote code execution. Sophos observed it being used as a targeted zero-day before the fix, and it's in CISA's KEV catalog. If your User Portal or Webadmin is exposed to the internet, this is patch-and-verify. Steady hands — but move.

At a glance

FactDetail
Our severity takeModerate — in practice (see below)
CVSS v3.1 (NVD)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.80% · 99.96th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2022-04-21
Known exploited?Yes — exploited as a targeted zero-day before the fix
Vulnerability typeAuthentication bypass (improper authentication) → remote code execution
Requires authenticated session?No — pre-authentication
AffectedSophos Firewall v18.5 MR3 (18.5.3) and older
Fixed inVendor hotfix (auto-installed by default), and later builds including v18.5 MR4 and v19.0

What you need to know

CVE-2022-1040 is an authentication bypass in the User Portal and Webadmin of Sophos Firewall. An unauthenticated remote attacker can slip past the authentication check on those web interfaces and, from there, reach remote code execution on the firewall.

Why the practical severity is at the top:

  • It's the firewall itself. Code execution on the perimeter device means an attacker can influence the thing enforcing your controls.
  • The vulnerable interfaces are often exposed. User Portal and Webadmin are web-facing by design, which is exactly the surface this bug abuses.
  • It was a real zero-day. Sophos observed exploitation against a small set of targeted organizations before a patch existed, so an affected, exposed device may have been touched pre-fix.

How serious we see it

Moderate — in practice.

Unauthenticated, network-reachable code execution on a security appliance, confirmed exploited in the wild, is top-of-queue. The 9.8 fits. The bounded, reassuring part is narrow scope and a clean fix path: it affects specific Sophos Firewall builds, the hotfix installs automatically for customers who left that setting enabled (the default), and reducing exposure is straightforward. The catch is the same as any pre-patch zero-day — being patched and being clean are separate questions, so hunt if you were exposed.

Recommendations

Straight from Sophos' advisory (SA-20220325-SFOS-RCE) and CISA:

  1. Confirm the hotfix applied, then patch. The hotfix auto-installs by default; verify it, and move to a fixed release (v18.5 MR4 / v19.0 or later).
  2. Take the portals off the WAN. Ensure User Portal and Webadmin aren't exposed to the internet; use VPN or Sophos Central for remote management.
  3. Hunt for prior use. Because exploitation predated the fix, review logs for anomalous authentication and administrative activity.
  4. If you find indicators, respond fully. Rotate credentials and secrets on the device and investigate for lateral movement.
  5. Confirm your exposure first. Verify whether you run an affected build with the portals reachable from the internet.

How BreachRisk sees it

BreachRisk discovers internet-facing Sophos Firewall User Portal and Webadmin interfaces from little more than your domain, fingerprints the product and version, and flags exposure tied to CVE-2022-1040 — raised to the top because it's in KEV. Where authorized, it goes a step past a scanner: it sends a safe, bounded check against the affected endpoint and looks only for the response that indicates the bypass path is present, confirming exposure without executing anything on the firewall.

That's the honest difference between "this build looks affected" and "we confirmed the exposed path responds" — surfaced continuously, so the exposed firewall is already mapped when a flaw like this breaks.

References

See your cyber risk, proven.