IT Support you can trust
  • Home
  • Our Services
    • Managed IT Support
    • Server Rooms
    • Virtualization
    • VoIP
    • Cyber Security
    • Cloud Techology
    • ERP-CRM
  • search
IT Support you can trust
IT Support you can trust
  • Home
  • Our Services
    • Managed IT Support
    • Server Rooms
    • Virtualization
    • VoIP
    • Cyber Security
    • Cloud Techology
    • ERP-CRM

 

 

A vulnerability (CVE-2022-1040) has been identified in Sophos Firewall prior to version 18.5 which could allow a malicious cyber actor to perform remote code execution. 

 

 

Alert status

 

HIGH

Background /What has happened?

A remote code execution (RCE) vulnerability (CVE-2022-1040) has been identified in User Portal and Webadmin of Sophos Firewall in versions 18.5 MR3 (18.5.3) and older. Sophos Firewall software provides network and user endpoint security. 

Exploitation of an RCE vulnerability could allow a malicious actor to remotely install malware or otherwise control the affected device.

Exploitation attempts have been observed. The ACSC is not aware of any successful exploitation attempts against Australian organisations.

Further information on this vulnerability, including available patches, is available in a Sophos security advisory.

Mitigation / How do I stay secure? 

Australian organisations who use Sophos Firewall versions prior to v18.5 should review their patch status and update to the latest version. 

Sophos Firewall have released a security advisory and hotfix for the affected Firewall versions.

Assistance / Where can I go for help? 

The ACSC is monitoring the situation and is able to provide assistance or advice as required. Organisations that have been impacted or require assistance can contact the ACSC via 1300 CYBER1 (1300 292 371). 

IT Support you can trust

Managed IT services enable businesses to outsource part or all of their technology management with the goal of simplifying IT operations and reducing costs.

Read More

Latest News

Java Threats link

Java Threats

.

Mobile Devices link

Mobile Devices

    A Remote Code Execution vulnerability has.

Item Tags

audio

Get in Touch

  • phone(357) 97 67 0001
  • emailinfo@a-one.com.cy
Copyright © 2026 IT Support you can trust - Designed by A1