Firewall Fiasco: Sophos and SonicWall Warn of Critical Security Flaws!

Sophos and SonicWall found critical security flaws that could lead to remote code execution. Sophos Firewall’s issues include a vulnerability that affects just 0.05% of devices—so rare, it’s practically an endangered species. SonicWall’s SMA 100 Series flaw remains unexploited, but users are advised to take precautions—better safe than hacked!

Pro Dashboard

Hot Take:

Security vulnerabilities are like the Kardashians of the cyber world—they just keep popping up and demanding our attention. This time, Sophos and SonicWall are in the spotlight for some juicy exploits that could make a hacker’s day. So, grab your popcorn and firewall updates, because this saga is far from over!

Key Points:

  • Sophos Firewall and SonicWall’s SMA 100 Series appliances have critical vulnerabilities that could lead to remote code execution.
  • Two Sophos vulnerabilities (CVE-2025-6704 and CVE-2025-7624) have a near-perfect CVSS score of 9.8.
  • SonicWall’s SMA 100 Series has a flaw (CVE-2025-40599) with a CVSS score of 9.1, posing a significant risk if exploited.
  • The U.K. NCSC discovered two other Sophos vulnerabilities affecting older firewall versions.
  • SonicWall suggests disabling remote management and enforcing multi-factor authentication (MFA) as part of their mitigation strategy.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?