CVE-2022-3236

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 4 articles

EPSS Score

Source: FIRST.org · 2026-05-24
92.84%
probability
This CVE has a 92.84% probability of being exploited in the next 30 days.
0% Top 99.8th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Code injection allowing RCE

Attack Intelligence

Google Project Zero

Discovered
Sept. 16, 2022
Patched
Sept. 23, 2022
Reported by
Sophos X-Ops
Root Cause Analysis
???

Signal Intelligence

Confidence
92%
EPSS 92.84%
Mentions 4
Last Seen Oct 11, 2022

CNA Information

Analyst Note

This CVE is confirmed by multiple credible sources including Google Project Zero and CERT-EU, with a critical CVSS score of 9.8 reflecting remote code execution impact in Sophos Firewall. The presence of official security advisories from established authorities provides strong corroboration of the vulnerability's authenticity and severity.

Threat Actors 24

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Turla Group
apt_group Information theft and espionage Russian Federation
APT 29
apt_group Information theft and espionage 🇷🇺 RU
Cobalt
apt_group Financial crime 🇷🇺 RU
APT37
apt_group Information theft and espionage 🇰🇵 KP
APT 28
apt_group Information theft and espionage 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
SaintBear
apt_group Information theft and espionage 🇷🇺 RU
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Hacking Team
apt_group 🇮🇹 IT
GhostEmperor
apt_group Information theft and espionage 🇨🇳 CN
UAC-0020
apt_group 🇺🇦 UA
Infy
apt_group Information theft and espionage 🇮🇷 IR
SideWinder
apt_group 🇮🇳 IN
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
FamousSparrow
apt_group Information theft and espionage 🇨🇳 CN
Larva-208
apt_group 🇷🇺 RU
FIN8
apt_group Financial crime 🇷🇺 RU
Operation Cobalt Whisper
apt_group Financial crime 🇨🇳 CN
UNC4841
apt_group Information theft and espionage 🇨🇳 CN
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
DEV-0586
apt_group Sabotage and destruction 🇷🇺 RU

Triage Info

Decided atMar 03, 2026