CVE-2026-18367: Sophos Endpoint For macOS

Critical severity, CVSS 9.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.

Affected products

  • Sophos Sophos Endpoint For macOS: before 2026.1.1 (fixed in 2026.1.1)
  • Sophos Sophos Home For macOS: before 10.11.6 (fixed in 10.11.6)

Published 2026-08-06. Last modified 2026-09-01.