Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Sophos’s July 21, 2025 security advisory covers five Sophos Firewall vulnerabilities: CVE-2025-6704 and CVE-2025-7624 (critical), CVE-2025-7382 and CVE-2024-13974 (high), and CVE-2024-13973 (medium). The affected versions and attack conditions differ, so administrators should check each firewall’s exact SFOS release and configuration against Sophos’s advisory and remediation table.
Which Sophos Firewall vulnerabilities did the July 2025 advisory address?
The notice describes three issues affecting Sophos Firewall v21.5 GA (21.5.0) and older, and two affecting v21.0 GA (21.0.0) and older. The table summarizes each vulnerability’s severity, prerequisites, affected-version range, and the first maintenance release Sophos says included its fix. Sophos’s advisory also lists hotfix publication dates by maintenance release; use those entries to check a particular installation rather than relying on the broad version thresholds alone.
| CVE and severity | What an attacker would need or exploit | Affected versions listed by Sophos | First release listed as including the fix |
|---|---|---|---|
| CVE-2025-6704 — Critical | An arbitrary file-writing flaw in Secure PDF eXchange (SPX) could enable pre-authentication remote code execution when a specific SPX configuration is enabled and the firewall is in High Availability (HA) mode. Sophos estimated it affected about 0.05% of devices in 2025. | v21.5 GA (21.5.0) and older | v21.0 MR2 and newer |
| CVE-2025-7624 — Critical | SQL injection in the legacy transparent SMTP proxy could lead to remote code execution when an email-quarantining policy is active and the SFOS installation was upgraded from a version older than v21.0 GA. Sophos estimated it affected at most 0.73% of devices in 2025. | v21.5 GA (21.5.0) and older | v21.0 MR2 and newer |
| CVE-2025-7382 — High | A WebAdmin command-injection flaw could allow pre-authentication code execution by an adjacent attacker on an HA auxiliary device when OTP authentication is enabled for the administrator. Sophos estimated it affected about 1% of devices in 2025. | v21.5 GA (21.5.0) and older | v21.0 MR2 and newer |
| CVE-2024-13974 — High | A business-logic flaw in Up2Date could permit remote code execution by an attacker who controls the firewall’s DNS environment. Sophos credited the UK’s National Cyber Security Centre for responsible disclosure. | v21.0 GA (21.0.0) and older | v21.0 MR1 and newer |
| CVE-2024-13973 — Medium | A post-authentication SQL injection in WebAdmin could potentially let an administrator achieve arbitrary code execution. Sophos credited the UK’s National Cyber Security Centre for responsible disclosure. | v21.0 GA (21.0.0) and older | v21.0 MR1 and newer |
Severity and prevalence figures in this table are from Sophos’s 2025 advisory. The percentages are Sophos estimates, not independent measurements; they do not indicate whether a particular firewall is vulnerable. Exposure depends on the installed release and, for several flaws, specific features or configuration.
How to check and remediate a firewall
- Identify the exact SFOS version and maintenance release on each firewall, including HA appliances. Record the installed release rather than treating all v21 installations as equivalent.
- Compare that release with Sophos’s per-CVE remediation entries in the July 2025 advisory. The first-fix thresholds differ: v21.0 MR2 and newer for the three 2025 CVEs in the table, and v21.0 MR1 and newer for the two 2024 CVEs. Check the advisory’s hotfix publication entries for the maintenance release installed on your device.
- Confirm the relevant hotfixes are installed. Sophos directs administrators to its support verification guidance from the advisory. Do not assume a firewall has every required fix just because it received one hotfix: Sophos’s hotfix documentation says more than one hotfix may be needed to fully address a vulnerability.
- Upgrade an unsupported or too-old installation to a supported release that receives current protections. Sophos says older versions must be upgraded to receive current protections; use the vendor’s guidance for the specific appliance and release.
- Review whether the affected conditions apply: SPX and HA configuration; legacy SMTP proxy and quarantine settings; OTP for WebAdmin administrators and HA auxiliary setup; and who can control the firewall’s DNS environment. This helps prioritize investigation, but does not replace applying the relevant fix.
Keep Sophos hotfixes enabled
Sophos describes hotfixes as security updates specific to each SFOS version. Its documentation says the hotfix setting is enabled by default, hotfixes are designed to install without a restart, and in HA clusters the primary receives the update and synchronizes it to the auxiliary. Sophos recommends keeping the setting enabled: “We recommend that you keep the hotfix setting on to make sure the firewall receives security updates.” See Sophos Hotfix: Security updates documentation for the product guidance.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- XGS 88 (Hardware Only) - Next-generation firewall appliance only; add a Sophos subscription to enable IPS, web security, VPN, and advanced threat defense.
- Equipped with 4 x 2.5 GE copper ports, supporting up to 9.9 Gbps firewall performance for small offices and branch deployments.
- Purpose built next generation firewall hardware engineered for high performance, visibility, and reliable operation in business networks.
- SD-WAN optimization provides resilient connectivity and intelligent traffic routing across multiple WAN connections.
- VPN ready architecture supports secure site to site networking and encrypted remote employee access.
What Sophos said about exploitation
In the July 21, 2025 advisory, Sophos said it had not observed these vulnerabilities being exploited at that time. That is a statement about the situation when the notice was issued, not confirmation of their exploitation status on October 4, 2026. The advisory also should not be read as a complete history of Sophos Firewall security updates: it covers this five-CVE group, and the sources cited here do not establish whether later advisories have been published.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Do not confuse this with Sophos’s December 2024 advisory
Sophos published a separate notice on December 19, 2024 for CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729, also affecting v21.0 GA and older. It reported two critical flaws and one high-severity flaw; CERT-EU’s December 20 notice reported CVSS scores of 9.8 for CVE-2024-12727 and CVE-2024-12728, and 8.8 for CVE-2024-12729. These are not three additional vulnerabilities in the July 2025 advisory.
Rank #2
- XGS 118 (Hardware Only) - Next-generation firewall appliance only; add a Sophos subscription to enable IPS, web security, VPN, and advanced threat defense.
- 9 x 2.5 GE copper ports and 1 SFP fiber port, delivering up to 15.5 Gbps firewall performance for mid sized organizations.
- Purpose built next generation firewall hardware engineered for high performance, visibility, and reliable operation in business networks.
- SD-WAN optimization provides resilient connectivity and intelligent traffic routing across multiple WAN connections.
- VPN ready architecture supports secure site to site networking and encrypted remote employee access.
The earlier notice described CVE-2024-12727 as conditional on a particular SPX configuration with HA; CVE-2024-12728 involved a suggested HA initialization SSH passphrase that was not random and remained active after setup when SSH was enabled; and CVE-2024-12729 was post-authentication code injection in the User Portal. For the SSH issue, Sophos advised restricting SSH to the dedicated HA link or using a long, random custom passphrase. For the other issues, it advised avoiding WAN exposure of User Portal and WebAdmin. See the Sophos December 2024 advisory and CERT-EU advisory for their hotfixes and workarounds.
Quick Recap
Best Value
- XGS 128 (Hardware Only) - Next-generation firewall appliance only; add a Sophos subscription to enable IPS, web security, VPN, and advanced threat defense.
- 9 x 2.5 GE copper ports and 1 SFP fiber port, providing up to 19.1 Gbps firewall throughput for larger offices.
- Purpose built next generation firewall hardware engineered for high performance, visibility, and reliable operation in business networks.
- SD-WAN optimization provides resilient connectivity and intelligent traffic routing across multiple WAN connections.
- VPN ready architecture supports secure site to site networking and encrypted remote employee access.
Rank #4
- XGS 118 with 3 Years Standard Protection - Next-generation firewall appliance with Standard Protection subscription providing firewall, VPN, intrusion prevention, web security, and application control, managed through Sophos Central for unified policies and reporting.
- 9 x 2.5 GE copper ports and 1 SFP fiber port, delivering up to 15.5 Gbps firewall performance for mid sized organizations.
- Protects users from ransomware, malware, phishing, and intrusion attempts before they reach endpoints or applications.
- SD-WAN features deliver reliable, optimized application performance and intelligent multi link failover.
- Includes Standard Protection – Comprehensive security package with firewall, intrusion prevention, VPN, web security, and application control to defend against everyday threats and keep business operations safe.
Rank #3
- Network administrators' main fears are that SSL inspection will have a performance impact or cause something to break, impacting the user experience. Sophos Firewall removes the blind spots caused by encrypted traffic by allowing you to use SSL inspection while maintaining performance efficiency.
- TLS 1.3 Decryption: Remove an enormous blind spot with intelligent TLS inspection that’s fast and effective, supporting the latest standards with extensive exceptions and point-and-click policy tools to make your job easy.
- Deep Packet Inspection: Stop the latest ransomware and breaches with high-performance streaming deep packet inspection, including next-gen IPS, web protection, and app control, as well as deep learning and sandboxing powered by SophosLabs Intelix.
- Sophos Firewall and the XGS Series appliances with dedicated Xstream Flow Processors enable the ultimate in application acceleration, high-performance TLS inspection, and powerful threat protection
- Specifications: Firewall throughput: 35,000 Mbps| Firewall IMIX: 20,000 Mbps | Firewall Latency (64 byte UDP): 4 µs | IPS throughput: 7,000 Mbps | Threat Protection throughput: 1,400 Mbps
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

