# Sophos macOS Endpoint LPE flaw patched

Published: 2026-08-14 · Severity: routine
Canonical: https://vorant.io/reports/09bceb10-bea8-5207-88d3-32867004b088/sophos-macos-endpoint-lpe-flaw-patched

> A privilege-escalation vulnerability in Sophos Intercept X Endpoint and Sophos Home for macOS lets an attacker gain elevated privileges; patches are available.

The French national cybersecurity agency (ANSSI/CERT-FR) published an advisory regarding a privilege escalation vulnerability affecting Sophos macOS products, specifically Intercept X Endpoint (Central) versions prior to 2026.1.1 and Sophos Home versions prior to 10.11.6. The flaw, tracked as CVE-2026-18367, allows an attacker to elevate privileges on affected macOS systems.

Sophos disclosed the issue in its own security bulletin (sophos-sa-20260806-ep-macos-lpe) published on August 6, 2026. There is no indication in the advisory of active exploitation in the wild; this is a standard vendor-disclosed vulnerability requiring users to update to the fixed versions. Organizations using affected Sophos endpoint protection products on macOS should apply the vendor's patches as soon as feasible to mitigate the privilege escalation risk.

## Mentioned in this report

- Vulnerabilities: CVE-2026-18367

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1025

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/09bceb10-bea8-5207-88d3-32867004b088/sophos-macos-endpoint-lpe-flaw-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
