<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Intercept X Endpoint (Central) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/intercept-x-endpoint-central/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 14 Aug 2026 14:05:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/intercept-x-endpoint-central/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation Vulnerability in Sophos Endpoint Products for macOS</title><link>https://feed.craftedsignal.io/briefs/2026-08-sophos-lpe/</link><pubDate>Fri, 14 Aug 2026 14:05:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-sophos-lpe/</guid><description>A local privilege escalation vulnerability, tracked as CVE-2026-18367, affects multiple Sophos endpoint security products on macOS, potentially allowing authenticated local users to gain elevated system privileges.</description><content:encoded><![CDATA[<p>Sophos has released a security advisory concerning a local privilege escalation vulnerability, identified as CVE-2026-18367, affecting its endpoint security software on macOS. The vulnerability impacts Intercept X Endpoint (Central) versions prior to 2026.1.1 and Sophos Home versions prior to 10.11.6. This vulnerability allows an authenticated local attacker to escalate their privileges within the context of the affected product, potentially gaining higher system-level access than their original user permissions allow. Given that endpoint security software typically operates with significant system-level privileges to perform its protective functions, successful exploitation of this flaw could facilitate further malicious activity on the compromised host. Organizations utilizing these products on macOS systems are advised to apply the vendor-provided patches immediately to mitigate the risk of local privilege escalation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-18367 results in local privilege escalation on macOS systems running vulnerable versions of Sophos Intercept X or Sophos Home. An attacker who has already obtained initial low-privilege access to a system could leverage this flaw to gain elevated permissions, effectively bypassing local security controls and potentially accessing restricted system areas, sensitive data, or performing unauthorized administrative operations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Sophos Intercept X Endpoint (Central) for macOS to version 2026.1.1 or later.</li>
<li>Upgrade Sophos Home for macOS to version 10.11.6 or later.</li>
<li>Review the official vendor advisory (sophos-sa-20260806-ep-macos-lpe) for specific implementation guidance and confirmation of patch application.</li>
<li>Monitor local system logs for signs of anomalous process execution or unauthorized changes to system configuration following any identified authentication events.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>privilege-escalation</category><category>macos</category></item></channel></rss>