Skip to Content
Informational

Critical

Resolved LPE in Endpoint for macOS (CVE-2026-18367)

CVE(S)

CVE-2026-18367

PRODUCT(S)

Sophos Endpoint

Updated

2026 Aug 6

Article Version

1

First Published

2026 Aug 6

Publication ID

sophos-sa-20260806-ep-macos-lpe

Workaround

No

Overview

A local privilege escalation vulnerability in Sophos Endpoint products for macOS was recently discovered and responsibly disclosed to Sophos. It was reported via the Sophos bug bounty program by an external security researcher. The vulnerability has been fixed.

Sophos would like to thank Hillel Pinto of XM Cyber for responsibly disclosing this issue to Sophos.

The remediation prevented local users to execute arbitrary commands with root privileges and interfere with Sophos protection components on the affected device. There was no evidence that the vulnerability was exploited and to our knowledge no customers are impacted.

There is no action required for customers, as updates are installed automatically by default.

Applies to the following Sophos product(s) and version(s)

  • Sophos Intercept X Endpoint (Central) for macOS version 2026.1 and prior versions
  • Sophos Home for macOS version 10.11.5 and prior versions

Remediation

  • Fix included in Intercept X Endpoint (Central) for macOS version 2026.1.1 released August 5
  • Fix included in Sophos Home for macOS version 10.11.6 released August 6

Related Information

Sophos Logo

Sophos Responsible Disclosure Policy

To learn about Sophos security vulnerability disclosure policies and publications, see the Responsible Disclosure Policy.

Resolved LPE in Endpoint for MacOS (CVE-2021-25264) | Sophos