SophosCVE-2026-18367
Sophos Endpoint for macOS: privilege escalation
Critical9.3CVE-2026-18367 · Published Aug 6, 2026 · updated Sep 1, 2026
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Sophos Endpoint for macOS Product | < 2026.1.1 | 2026.1.1 |
| Sophos Home for macOS Product | < 10.11.6 | 10.11.6 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-285