SecurityWeek reports that updates have been issued by Sophos to address five Sophos Firewall flaws including a critical arbitrary file writing issue, tracked as CVE-2025-6704, and a critical SQL injection bug, tracked as CVE-2025-7624, which could be leveraged to facilitate remote code execution.Only a few Sophos Firewall instances are impacted by the vulnerabilities, with CVE-2025-6704 exploitable only in firewalls under High Availability mode and a particular Secure PDF eXchange configuration, while CVE-2025-7624 arises only in the event of an active quarantining policy for Email and a certain update for SFOS, according to Sophos. Also fixed were the high-severity command injection flaw, tracked as CVE-2025-7382, which could enable arbitrary code execution, as well as the Up2Date and WebAdmin component issues, tracked as CVE-2024-13974 and CVE-2024-13973. Organizations have been recommended to implement newer versions of the firewall to mitigate risks even if none of the patched flaws have been exploited in the wild.
Vulnerability Management, Patch/Configuration Management, Network Security
Multiple Sophos Firewall vulnerabilities resolved

An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



