Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2022-3236
Sophos Firewall
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .9890 99.9 YES
AFFECTED
Product Versions Fixed
Sophos Firewall unspecified – —
TIMELINE
Sep 17 Reserved by Sophos
Sep 23 Added to CISA KEV, remediation due 2022-10-14
Sep 23 Published (CNA: Sophos)
Description
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 17, 2022 | Reserved | Reserved by Sophos |
| September 23, 2022 | KEV ADDED | Added to CISA KEV, remediation due 2022-10-14 |
| September 23, 2022 | Published | Published (CNA: Sophos) |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Sophos | Sophos Firewall | — | unspecified | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2022-3236 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Monday, October 5, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.