CVE-2026-65400

CRITICAL(9.8)KEV

Apple macOS Improper Authentication Vulnerability

Description

CVE-2026-65400 is a critical improper authentication vulnerability in Apple macOS that allows an attacker on the network to authenticate to Screen Sharing without valid credentials. Rooted in flawed state management within the authentication flow, the vulnerability lets a remote, unauthenticated attacker bypass the credential check and gain access to a victim's Mac via Screen Sharing. Because Screen Sharing provides interactive control of the desktop, successful exploitation of this macOS authentication vulnerability can lead to full compromise of confidentiality, integrity, and availability. With a CVSS score of 9.8 and inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog, CVE-2026-65400 is a high-priority fix for all affected macOS systems.

KEV Information

Vendor
Apple
Product
macOS
Date Added
August 18, 2026
Due Date
August 21, 2026
Required Action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
applemacos>= 14.0, < 14.8.9; >= 15.0, < 15.7.9; >= 26.0, < 26.6.1

References

Weakness Type

CWE-287: Improper Authentication

Improper authentication occurs when a system does not adequately prove that a claimed identity is genuine, allowing attackers to bypass the authentication logic. In CVE-2026-65400 the macOS Screen Sharing authentication can be circumvented due to an issue in state management, so a network attacker is authenticated without supplying valid credentials.

Learn more: CWE-287 — Improper Authentication

Impact Analysis

The impact of CVE-2026-65400 is severe because it is remotely exploitable over the network with low attack complexity, requires no privileges, and needs no user interaction, meaning an attacker who can reach the Screen Sharing service can authenticate without credentials. A successful exploit produces high impact to confidentiality, integrity, and availability — once connected via Screen Sharing, the attacker can view and control the desktop, read and exfiltrate data, alter system state, and disrupt the machine. Given that Screen Sharing grants interactive remote control, this effectively means full takeover of the affected Mac. Rated CVSS 9.8 (Critical) with an EPSS score of roughly 0.8% (52nd percentile) and confirmed active exploitation per CISA, the vulnerability warrants immediate remediation despite the modest EPSS figure.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2026-65400 by adding it to the Known Exploited Vulnerabilities catalog, so this should be treated as an in-the-wild threat requiring prompt action. The EPSS score of about 0.8% (52nd percentile) is relatively modest, but the confirmed exploitation status means the practical risk is materially higher than the score alone implies. The KEV ransomware flag is "Unknown," and no dedicated public exploit link is listed among the references, though a full-disclosure mailing-list post and a national CERT advisory (NCSC-NL) discuss the issue. Given the confirmed exploitation and the interactive-control payoff of a Screen Sharing bypass, defenders should assume viable exploit techniques exist and prioritize patching and exposure reduction.

Remediation

  1. Install Apple's security update immediately. Per CISA's KEV required action, apply mitigations in accordance with vendor instructions and comply with BOD 26-04 guidance; if fixes are unavailable, discontinue use of the affected product.
  2. Upgrade to a fixed macOS version. Update to macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, or macOS Tahoe 26.6.1, which address the issue for the 15.x, 14.x, and 26.x lines respectively.
  3. Disable or restrict Screen Sharing where not required. Turn off Screen Sharing on systems that do not need it, and where it is required, restrict access to trusted management networks using firewalls to limit exposure until patching is complete.
  4. Monitor for unauthorized Screen Sharing sessions. Review system and remote-access logs for unexpected Screen Sharing connections or logins from unfamiliar network sources, which may indicate exploitation attempts.
  5. Harden remote access long term by enforcing strong, correctly validated authentication for all remote services and minimizing network exposure of macOS remote-management features.

Technical Details

CVE-2026-65400 is an improper authentication flaw (CWE-287) that Apple describes as an authentication issue addressed with improved state management. The Screen Sharing service fails to correctly verify the claimed identity because of a state-handling defect, so the authentication decision can be reached without valid credentials. The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H shows the attack is network-reachable, low-complexity, and requires neither privileges nor user interaction, which is why an attacker on the same network can complete authentication to Screen Sharing and obtain interactive control with high impact to confidentiality, integrity, and availability — all without any legitimate account on the target.

Frequently Asked Questions

Is CVE-2026-65400 being actively exploited?

Yes. CISA has added CVE-2026-65400 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Its EPSS score is about 0.8% (52nd percentile), but the confirmed exploitation status makes the real-world risk considerably higher.

What products are affected by CVE-2026-65400?

The vulnerability affects Apple macOS, specifically the 14.x line before 14.8.9 (Sonoma), the 15.x line before 15.7.9 (Sequoia), and the 26.x line before 26.6.1 (Tahoe). Systems with Screen Sharing reachable on the network are at greatest risk.

How do I fix CVE-2026-65400?

Update to macOS Sonoma 14.8.9, Sequoia 15.7.9, or Tahoe 26.6.1, depending on your version. Until patched, disable Screen Sharing where it is not needed and restrict its network exposure, following CISA's KEV/BOD 26-04 guidance.

How severe is CVE-2026-65400?

It is Critical, with a CVSS 3.1 base score of 9.8. The flaw is unauthenticated, network-exploitable, requires no user interaction, and grants interactive Screen Sharing control with high confidentiality, integrity, and availability impact; combined with confirmed active exploitation, it is a high-priority fix despite an EPSS score around the 52nd percentile.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score0.75%
EPSS Percentile52.2%

Dates

PublishedAugust 6, 2026
Last ModifiedAugust 19, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.