Sophos released security updates for Sophos Firewall to remediate three vulnerabilities affecting version 21.0 GA (21.0.0) and earlier, including two critical issues tracked as CVE-2024-12727 and CVE-2024-12728. According to public advisories, CVE-2024-12727 is an SQL injection flaw in the email protection feature that can expose the internal firewall database and, under specific HA and SPX conditions, lead to remote code execution. CVE-2024-12728 stems from an improperly handled SSH password used during HA cluster initialization that remains active after setup, potentially enabling unauthorized system access.
A third flaw, CVE-2024-12729, affects the User Portal and allows an authenticated remote attacker to perform command injection and achieve remote code execution. Sophos said devices with automatic hotfix installation enabled receive the fixes automatically, and the company published guidance for administrators to verify whether the hotfixes have been applied successfully. Organizations running affected firewall versions have been urged to confirm patch status promptly because the vulnerabilities impact perimeter security infrastructure and could expose management access or enable code execution on the device.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
Sophos published support guidance explaining how administrators can verify whether hotfixes for CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729 have been applied. The guidance complements Sophos's statement that devices with automatic hotfix installation enabled are patched automatically.
Sophos released security updates for Sophos Firewall to fix CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729. The flaws affect version 21.0 GA (21.0.0) and earlier and can enable unauthorized access, command injection, and remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.