AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18367

CRITICAL · CVSS 9.3 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A privilege escalation vulnerability in Sophos Endpoint and Sophos Home for macOS allows local users to execute arbitrary code with root privileges on affected versions prior to 2026.1.1 and 10.11.6, respectively. This critical flaw poses significant risks to system integrity and confidentiality, making it essential for organizations using these products to prioritize immediate updates to mitigate potential exploitation. Users of these Sophos solutions should take action to ensure they are running the latest versions to protect against this vulnerability.

CVE
CVE-2026-18367
Severity
CRITICAL
CVSS
9.3
EPSS
0.13%

Original NVD Description

A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.