Work at Sophos? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 3 Oct 2026.
Program Overview At Sophos, we understand the effort that goes into security research. To show our appreciation to researchers, who help keep our products and our customers safe, we are glad to introduce a Responsible Disclosure Program to provide recognition and rewards for responsibly disclosed vulnerabilities. Sophos rewards the responsible disclosure of any identified and confirmed security vulnerability that could be used to compromise the confidentiality, integrity, or availability of Sophos products, as well as services and infrastructure impacting Sophos' or users' data. In general no credentials or product keys will be provided for this program - all testing is to be performed using self-provisioned credentials against legally obtained Sophos products, including free trials. See the section Credentials for more details. The severity of submissions will be determined using CVSSv3.1 according to Sophos' internal standard.
Scope
23 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| 3rd party services hosted at *.sophos.com | website | ✓ bounty | not set |
| Any Other Sophos Product or Service | other | ✓ bounty | not set |
| Intercept X Endpoint (Linux) | other | ✓ bounty | not set |
| Intercept X Endpoint (MacOS) | other | ✓ bounty | not set |
| Intercept X Endpoint (Windows) | other | ✓ bounty | not set |
Show all 23 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| Intercept X Endpoint (Windows) - Zero-click RCE | other | ✓ bounty | not set |
| Intercept X Mobile (Android) | android | ✓ bounty | not set |
| Intercept X Mobile (iOS) | ios | ✓ bounty | not set |
| Other Sophos Appliances (RED, Switch, Access Points, ...) | iot | ✓ bounty | not set |
| Sophos Central (Production) | website | ✓ bounty | not set |
| Sophos Central (Production) - Special Target | website | ✓ bounty | not set |
| Sophos Firewall (XG/XGS, SFOS) | iot | ✓ bounty | not set |
| Sophos Firewall (XG/XGS, SFOS) - Pre-auth RCE | iot | ✓ bounty | not set |
| Sophos IT Infrastructure (all other Sophos domains) | other | ✓ bounty | not set |
| Sophos NDR Appliances (NDR, Investigation Console) | iot | ✓ bounty | not set |
| Sophos-owned IT infrastructure (*.sophos.com) | network | ✓ bounty | not set |
| SOPHOS/Secureworks : Redcloak | other | ✓ bounty | not set |
| SOPHOS/Secureworks : Taegis | other | ✓ bounty | not set |
| Any Cyberoam Product or Service | other | out | not set |
| community.sophos.com | website | out | not set |
| Sophos Firewall (Early Access Program (EAP) versions) | iot | out | not set |
| sophos.atlassian.net (Public service desk) | website | out | not set |
| SPF/DKIM/DMARC issues | other | out | not set |