{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/sophos-home/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-18367"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Intercept X Endpoint (Central)","Sophos Home"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation","macos"],"_cs_type":"advisory","_cs_vendors":["Sophos"],"content_html":"\u003cp\u003eSophos has released a security advisory concerning a local privilege escalation vulnerability, identified as CVE-2026-18367, affecting its endpoint security software on macOS. The vulnerability impacts Intercept X Endpoint (Central) versions prior to 2026.1.1 and Sophos Home versions prior to 10.11.6. This vulnerability allows an authenticated local attacker to escalate their privileges within the context of the affected product, potentially gaining higher system-level access than their original user permissions allow. Given that endpoint security software typically operates with significant system-level privileges to perform its protective functions, successful exploitation of this flaw could facilitate further malicious activity on the compromised host. Organizations utilizing these products on macOS systems are advised to apply the vendor-provided patches immediately to mitigate the risk of local privilege escalation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-18367 results in local privilege escalation on macOS systems running vulnerable versions of Sophos Intercept X or Sophos Home. An attacker who has already obtained initial low-privilege access to a system could leverage this flaw to gain elevated permissions, effectively bypassing local security controls and potentially accessing restricted system areas, sensitive data, or performing unauthorized administrative operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Sophos Intercept X Endpoint (Central) for macOS to version 2026.1.1 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade Sophos Home for macOS to version 10.11.6 or later.\u003c/li\u003e\n\u003cli\u003eReview the official vendor advisory (sophos-sa-20260806-ep-macos-lpe) for specific implementation guidance and confirmation of patch application.\u003c/li\u003e\n\u003cli\u003eMonitor local system logs for signs of anomalous process execution or unauthorized changes to system configuration following any identified authentication events.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T14:05:58Z","date_published":"2026-08-14T14:05:58Z","id":"https://feed.craftedsignal.io/briefs/2026-08-sophos-lpe/","summary":"A local privilege escalation vulnerability, tracked as CVE-2026-18367, affects multiple Sophos endpoint security products on macOS, potentially allowing authenticated local users to gain elevated system privileges.","title":"Privilege Escalation Vulnerability in Sophos Endpoint Products for macOS","url":"https://feed.craftedsignal.io/briefs/2026-08-sophos-lpe/"}],"language":"en","title":"CraftedSignal Threat Feed - Sophos Home","version":"https://jsonfeed.org/version/1.1"}