CVE-2026-18367: Critical severity Sophos Sophos Endpoint for macOS vulnerability
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sophos Endpoint for macOSto a version that resolves this vulnerability.Fixed in 2026.1.1 - Upgrade
Upgrade
Sophos Home for macOSto a version that resolves this vulnerability.Fixed in 10.11.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18367?
The severity of CVE-2026-18367 is critical with a CVSS score of 9.3.
How do I fix CVE-2026-18367?
To fix CVE-2026-18367, upgrade Sophos Endpoint for macOS to version 2026.1.1 or later and Sophos Home for macOS to version 10.11.6 or later.
Who is affected by CVE-2026-18367?
Local users of Sophos Endpoint for macOS versions prior to 2026.1.1 and Sophos Home for macOS versions prior to 10.11.6 are affected by CVE-2026-18367.
What type of vulnerability is CVE-2026-18367?
CVE-2026-18367 is a privilege escalation vulnerability that allows local users to execute arbitrary code as root.
When was CVE-2026-18367 published?
CVE-2026-18367 was published on August 6, 2026.