CVE-2024-13861: Sophos Taegis Endpoint Agent
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitrary code execution as root. Redhat-based systems using RPM packages are not affected.
Affected products
- Sophos Taegis Endpoint Agent: before 1.3.10 (fixed in 1.3.10)
Published 2025-04-11. Last modified 2026-06-17.