Sophos macOS Endpoint LPE flaw patched
A privilege-escalation vulnerability in Sophos Intercept X Endpoint and Sophos Home for macOS lets an attacker gain elevated privileges; patches are available.
The French national cybersecurity agency (ANSSI/CERT-FR) published an advisory regarding a privilege escalation vulnerability affecting Sophos macOS products, specifically Intercept X Endpoint (Central) versions prior to 2026.1.1 and Sophos Home versions prior to 10.11.6. The flaw, tracked as CVE-2026-18367, allows an attacker to elevate privileges on affected macOS systems.
Sophos disclosed the issue in its own security bulletin (sophos-sa-20260806-ep-macos-lpe) published on August 6, 2026. There is no indication in the advisory of active exploitation in the wild; this is a standard vendor-disclosed vulnerability requiring users to update to the fixed versions. Organizations using affected Sophos endpoint protection products on macOS should apply the vendor's patches as soon as feasible to mitigate the privilege escalation risk.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1025
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free