openPR Logo
Press release

Sophos CVEs July 2025: Immediate updates for Firewall and Intercept X recommended

07-23-2025 11:44 AM CET | IT, New Media & Software

Press release from: Aphos GmbH

Symbolic representation of the CVEs for Sophos Firewall, Endpoint & Server Protection. (© Aphos GmbH / Firewalls24)

Symbolic representation of the CVEs for Sophos Firewall, Endpoint & Server Protection. (© Aphos GmbH / Firewalls24)

In July 2025, Sophos has fixed several critical vulnerabilities in Sophos Firewall (SFOS) and Intercept X for Endpoint and Server. The vulnerabilities, including remote code execution (RCE) and privilege escalation, were closed by hotfixes and updates. Systems with automatic hotfix installation enabled are already secured. Users with Fixed Term Support (FTS) or Long Term Support (LTS) must update their systems manually to ensure full protection.

Affected Sophos products and CVEs

Sophos Firewall (SFOS)

* CVE-2025-6704: SPX file write with RCE potential (critical)
* CVE-2025-7624: SQL injection in transparent SMTP proxy (critical)
* CVE-2025-7382: Command injection in WebAdmin (high)
* CVE-2024-13974: Business logic vulnerability in Up2Date (high)
* CVE-2024-13973: SQL injection after authentication in WebAdmin (medium)

Sophos Intercept X for Endpoint & Server

* CVE-2024-13972: Incorrect registry permissions (high)
* CVE-2025-7433: Privilege escalation in Device Encryption (high)
* CVE-2025-7472: Privilege escalation in Installer (high)

Recommendations for action

Sophos strongly recommends checking installed versions and hotfixes to eliminate the risk of active attacks. Sophos Firewall in particular should have the latest hotfix HF071525.1 installed. For Intercept X, at least versions 2024.3.2 (Endpoint), 2025.1 (Device Encryption) and the installer from version 1.22 should be used.

Detailed information on the individual CVEs, hotfixes and highly recommended updates can be found on Firewalls24.

Update strategies for companies

The current CVEs underline the importance of continuous patch management. Organizations that do not update their systems regularly risk significant security vulnerabilities. Aphos GmbH's Professional Service offers Service Level Agreements (SLAs) that ensure automatic updates and proactive security checks - including ongoing maintenance of Sophos firewalls and endpoint and server solutions.

Aphos Gesellschaft für IT-Sicherheit mbH
Mergenthalerallee 73-75
Eschborn 65760
Germany

https://aphos.de/
https://firewalls24.de/

Herr Lennart Wyrwa
061965820160
marketing@aphos.de

Aphos Gesellschaft für IT-Sicherheit mbH is a specialized IT security provider with a focus on tailor-made cybersecurity solutions for companies, authorities and public institutions. As an accredited Sophos Platinum Partner, the company offers first-class consulting, comprehensive support and a broad portfolio of IT security solutions.

With Firewalls24.de, the store for IT security solutions from Sophos, Aphos GmbH enables fast and uncomplicated procurement of Sophos firewalls, switches, access points and Sophos Central licenses.

The combination of technical expertise, personal advice and great prices makes Aphos the ideal partner for companies of all sizes that rely on the highest security standards.

This release was published on openPR.

Permanent link to this press release:

Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.

You can edit or delete your press release Sophos CVEs July 2025: Immediate updates for Firewall and Intercept X recommended here

News-ID: 4115995 • Views:

More Releases from Aphos GmbH

CIS Controls v8.1 integrated into Sophos Central Assessment Tool
CIS Controls v8.1 integrated into Sophos Central Assessment Tool
The assessment tool in Sophos Central now also supports the latest CIS Controls v8.1, adding another internationally recognized standard for assessing cybersecurity maturity to the functionality of Sophos's self-assessment platform. This provides organizations with a practical tool to evaluate and prioritize protection measures in a structured manner and align them with established frameworks such as CIS, NIST or NIS-2. CIS Controls v8.1: Internationally recognized security framework The CIS Controls (Center for Internet

More Releases for Sophos

CIS Controls v8.1 integrated into Sophos Central Assessment Tool
The assessment tool in Sophos Central now also supports the latest CIS Controls v8.1, adding another internationally recognized standard for assessing cybersecurity maturity to the functionality of Sophos's self-assessment platform. This provides organizations with a practical tool to evaluate and prioritize protection measures in a structured manner and align them with established frameworks such as CIS, NIST or NIS-2. CIS Controls v8.1: Internationally recognized security framework The CIS Controls (Center for Internet
Internet Security Market to Eyewitness Massive Growth with Sophos, Dell, Fortine …
The Latest research study released by HTF MI "Global Internet Security Market with 120+ pages of analysis on business Strategy taken up by key and emerging industry players and delivers know-how of the current market development, landscape, technologies, drivers, opportunities, market viewpoint, and status. Understanding the segments helps in identifying the importance of different factors that aid market growth. Some of the Major Companies covered in this Research are Sophos,
Encryption Software Market to Witness Stunning Growth | IBM, Microsoft, Sophos
The Latest Released Encryption Software market study has evaluated the future growth potential of Encryption Software market and provides information and useful stats on market structure and size. The report is intended to provide market intelligence and strategic insights to help decision-makers take sound investment decisions and identify potential gaps and growth opportunities. Additionally, the report also identifies and analyses changing dynamics, and emerging trends along with essential drivers, challenges,
Enterprise Firewall Market Is Thriving Worldwide with Sophos, Dell, Cisco, Micro …
Advance Market Analytics added research publication document on Worldwide Enterprise Firewall Market breaking major business segments and highlighting wider level geographies to get deep dive analysis on market data. The study is a perfect balance bridging both qualitative and quantitative information of Worldwide Enterprise Firewall market. The study provides valuable market size data for historical (Volume** & Value) from 2016 to 2020 which is estimated and forecasted till 2026*. Some
BFSI Security Market Boosting the Growth Worldwide | IBM, McAfee, Sophos
Advance Market Analytics published a new research publication on “BFSI Security Market Insights, to 2026″ with 232 pages and enriched with self-explained Tables and charts in presentable format. In the Study you will find new evolving Trends, Drivers, Restraints, Opportunities generated by targeting market associated stakeholders. The growth of the BFSI Security Market was mainly driven by the increasing R&D spending across the world. Some of the key players profiled in
Web-Scale IT Market is Booming Worldwide | IBM, Sophos, Symantec
Advance Market Analytics published a new research publication on “Web-Scale IT Market Insights, to 2026″ with 232 pages and enriched with self-explained Tables and charts in presentable format. In the Study you will find new evolving Trends, Drivers, Restraints, Opportunities generated by targeting market associated stakeholders. The growth of the Web-Scale IT Market was mainly driven by the increasing R&D spending across the world. Some of the key players profiled in