CVE-2022-3236
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
4 articles
EPSS Score
Source: FIRST.org · 2026-05-24
92.84%
probability
This CVE has a 92.84% probability
of being exploited in the next 30 days.
0%
Top 99.8th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroCode injection allowing RCE
Attack Intelligence
Google Project Zero
Discovered
Sept. 16, 2022
Patched
Sept. 23, 2022
Reported by
Sophos X-Ops
Root Cause Analysis
???
Security Advisory 2022-065
CERT-EU
Sep 26, 2022
Qualys Research Team: Threat Thursdays, September 2022
Qualys
Sep 29, 2022
Signal Intelligence
Confidence
92%
EPSS
92.84%
Mentions
4
Last Seen
Oct 11, 2022
CNA Information
Analyst Note
This CVE is confirmed by multiple credible sources including Google Project Zero and CERT-EU, with a critical CVSS score of 9.8 reflecting remote code execution impact in Sophos Firewall. The presence of official security advisories from established authorities provides strong corroboration of the vulnerability's authenticity and severity.
Threat Actors 24
MuddyWater
apt_group
Information theft and espionage
🇮🇷 IR
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
Turla Group
apt_group
Information theft and espionage
Russian Federation
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT37
apt_group
Information theft and espionage
🇰🇵 KP
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Kimsuky
apt_group
Information theft and espionage
🇰🇷 KR
SaintBear
apt_group
Information theft and espionage
🇷🇺 RU
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Hacking Team
apt_group
🇮🇹 IT
GhostEmperor
apt_group
Information theft and espionage
🇨🇳 CN
UAC-0020
apt_group
🇺🇦 UA
Infy
apt_group
Information theft and espionage
🇮🇷 IR
SideWinder
apt_group
🇮🇳 IN
RAZOR TIGER
apt_group
Information theft and espionage
🇮🇳 IN
FamousSparrow
apt_group
Information theft and espionage
🇨🇳 CN
Larva-208
apt_group
🇷🇺 RU
FIN8
apt_group
Financial crime
🇷🇺 RU
Operation Cobalt Whisper
apt_group
Financial crime
🇨🇳 CN
UNC4841
apt_group
Information theft and espionage
🇨🇳 CN
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
DEV-0586
apt_group
Sabotage and destruction
🇷🇺 RU
Triage Info
Decided atMar 03, 2026