CVE-2026-18367 – Sophos Endpoint for macOS
CVSS 9.3
CRITICAL
Critical - Same Day Deployment
“A local foothold can become full root control on vulnerable Sophos-protected Macs.”
CVE-2026-18367 is a Critical privilege escalation vulnerability affecting Sophos Endpoint for macOS before version 2026.1.1 and Sophos Home for macOS before version 10.11.6. The CVSS score is 9.3, which is Critical severity. A local user can exploit the vulnerability to execute arbitrary code with root privileges.
Sophos Endpoint for macOS 2026.1.1 and Sophos Home for macOS 10.11.6 address the vulnerability.
Key Details
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-285
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.