CVE-2026-18367 – Sophos Endpoint for macOS

CVSS 9.3 CRITICAL Critical - Same Day Deployment

“A local foothold can become full root control on vulnerable Sophos-protected Macs.”

CVE-2026-18367 is a Critical privilege escalation vulnerability affecting Sophos Endpoint for macOS before version 2026.1.1 and Sophos Home for macOS before version 10.11.6. The CVSS score is 9.3, which is Critical severity. A local user can exploit the vulnerability to execute arbitrary code with root privileges.

Sophos Endpoint for macOS 2026.1.1 and Sophos Home for macOS 10.11.6 address the vulnerability.

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-285
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.