Known Vulnerabilities for Web Appliance by Sophos

Listed below are 10 of the newest known vulnerabilities associated with "Web Appliance" by "Sophos".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

More device details and information can be found at device.report here: Sophos Web Appliance

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-42930 json When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance m... Not Provided 2026-05-13 2026-05-13
CVE-2026-41217 json A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resou... Not Provided 2026-05-13 2026-05-13
CVE-2026-40061 json When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command t... Not Provided 2026-05-13 2026-05-13
CVE-2026-34176 json When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl RES... Not Provided 2026-05-13 2026-05-13
CVE-2026-32673 json A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator o... Not Provided 2026-05-13 2026-05-13
CVE-2026-27101 json Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application version(s) 5.28.00.xx to 5.32.00.xx, contain(s) an Improper L... Not Provided 2026-04-01 2026-04-02
CVE-2026-24464 json When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may ... Not Provided 2026-05-13 2026-05-13
CVE-2026-20152 json A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an... Not Provided 2026-04-15 2026-04-16
CVE-2026-20106 json A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Securi... Not Provided 2026-03-04 2026-03-11
CVE-2026-20105 json A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Softwar... Not Provided 2026-03-04 2026-03-04

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationSophosWeb Appliance4.3.1.1
ApplicationSophosWeb Appliance3.8.1
ApplicationSophosWeb Appliance3.8.0
ApplicationSophosWeb Appliance3.7.9
ApplicationSophosWeb Appliance3.7.8.2
ApplicationSophosWeb Appliance3.7.8.1
ApplicationSophosWeb Appliance3.7.8
ApplicationSophosWeb Appliance3.7.7
ApplicationSophosWeb Appliance3.7.6
ApplicationSophosWeb Appliance3.7.5
ApplicationSophosWeb Appliance3.7.4
ApplicationSophosWeb Appliance3.7.3
ApplicationSophosWeb Appliance3.7.2
ApplicationSophosWeb Appliance3.7.1
ApplicationSophosWeb Appliance3.7.0
ApplicationSophosWeb Appliance3.6.4.2
ApplicationSophosWeb Appliance3.6.4.1
ApplicationSophosWeb Appliance3.6.4
ApplicationSophosWeb Appliance3.6.3
ApplicationSophosWeb Appliance3.6.2.4.1
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report