Skip to content

Sophos vulnerabilities

1 CVE tracked

Sophos appears in current reporting both as a security researcher and as a vendor with a product vulnerability. The company's research highlights that rapidly adopted AI agents are an expanding attack surface, while compromised credentials have surpassed software vulnerabilities as the primary entry vector for ransomware. Regarding its own products, a critical privilege escalation vulnerability (CVE-2026-18367) impacts Sophos Endpoint and Sophos Home on macOS, allowing local code execution as root. Defenders should prioritize patching macOS endpoints for this CVE and remain vigilant against malware campaigns impersonating AI brands.

This vendor's CVEs1

This hub is built from skopnix's own reporting on Sophos: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.