Firewall Fiasco: Sophos and SonicWall Warn of Critical Security Flaws!
Sophos and SonicWall found critical security flaws that could lead to remote code execution. Sophos Firewall’s issues include a vulnerability that affects just 0.05% of devices—so rare, it’s practically an endangered species. SonicWall’s SMA 100 Series flaw remains unexploited, but users are advised to take precautions—better safe than hacked!

Hot Take:
Security vulnerabilities are like the Kardashians of the cyber world—they just keep popping up and demanding our attention. This time, Sophos and SonicWall are in the spotlight for some juicy exploits that could make a hacker’s day. So, grab your popcorn and firewall updates, because this saga is far from over!
Key Points:
- Sophos Firewall and SonicWall’s SMA 100 Series appliances have critical vulnerabilities that could lead to remote code execution.
- Two Sophos vulnerabilities (CVE-2025-6704 and CVE-2025-7624) have a near-perfect CVSS score of 9.8.
- SonicWall’s SMA 100 Series has a flaw (CVE-2025-40599) with a CVSS score of 9.1, posing a significant risk if exploited.
- The U.K. NCSC discovered two other Sophos vulnerabilities affecting older firewall versions.
- SonicWall suggests disabling remote management and enforcing multi-factor authentication (MFA) as part of their mitigation strategy.
Already a member? Log in here