Critical authentication-bypass vulnerability CVE-2025-10159 affects Sophos AP6 Series firmware before 1.7.2563 (MR7). Patch released in 1.7.2563; devices with automatic updates will be patched. Organisations with automatic updates disabled must upgrade immediately. No workaround available.
Sophos has patched three high-severity local privilege escalation flaws (CVE-2024-13972, CVE-2025-7433, CVE-2025-7472). Upgrade Endpoint and Workload Protection to fixed versions (Core Agent 2024.3.2, Device Encryption 2025.1, Installer 1.22). Replace installers downloaded before 6 March 2025; no workarounds.