THREAT OPS › CVEs › CVE-2026-65400
CVE-2026-65400 — Apple macOS Improper Authentication Vulnerability
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
Vulnerability details
- Affected productsmacOS
- KEV remediation due2026-08-21
Related reporting
- The Apple Security Update Review for September 2026zdi_blog
- [NVD] CVE-2026-65400 (CRITICAL 9.8) — An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valnvd
- August 2026 CVE Landscaperecordedfuture
- Windows IKE CVE-2026-33824 Added to CISA KEVsocradar_blog
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitationthehackernews
- CISA Adds Four Known Exploited Vulnerabilities to Catalogcisa_advisories
- From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOShuntress
- [CISA KEV] CVE-2026-65400 — Apple macOS: Apple macOS Improper Authentication Vulnerabilitycisa_kev
- Apple security advisory (AV26-823)cccs_ca
- 17th August – Threat Intelligence Reportcheckpoint_research
- Update your Mac: Screen Sharing vulnerability exploited in the wildmalwarebytes_blog
- Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Minerthehackernews