VORANT. Threat Intelligence Sign in Get the full feed

Sophos macOS Endpoint LPE flaw patched

routine vulnerability

A privilege-escalation vulnerability in Sophos Intercept X Endpoint and Sophos Home for macOS lets an attacker gain elevated privileges; patches are available.

The French national cybersecurity agency (ANSSI/CERT-FR) published an advisory regarding a privilege escalation vulnerability affecting Sophos macOS products, specifically Intercept X Endpoint (Central) versions prior to 2026.1.1 and Sophos Home versions prior to 10.11.6. The flaw, tracked as CVE-2026-18367, allows an attacker to elevate privileges on affected macOS systems.

Sophos disclosed the issue in its own security bulletin (sophos-sa-20260806-ep-macos-lpe) published on August 6, 2026. There is no indication in the advisory of active exploitation in the wild; this is a standard vendor-disclosed vulnerability requiring users to update to the fixed versions. Organizations using affected Sophos endpoint protection products on macOS should apply the vendor's patches as soon as feasible to mitigate the privilege escalation risk.

Mentioned in this report

Vulnerabilities CVE-2026-18367

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1025

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free