Critical severity9.8CISA KEVNVD Advisory· Published Aug 6, 2026· Updated Sep 15, 2026
CVE-2026-65400
CVE-2026-65400
Description
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Affected products
2cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*range: >=14.0,<14.8.9
- (no CPE)range: >=27, >=15.7.9, >=14.8.9, >=26.6.1, >=26.7
Patches
Vulnerability mechanics
References
9- advisories.ncsc.nl/2026/ncsc-2026-0280.htmlnvdThird Party Advisory
- support.apple.com/en-us/148170nvdRelease NotesVendor Advisory
- support.apple.com/en-us/148171nvdRelease NotesVendor Advisory
- support.apple.com/en-us/148172nvdRelease NotesVendor Advisory
- support.apple.com/en-us/149035nvdRelease NotesVendor Advisory
- support.apple.com/en-us/149042nvdRelease NotesVendor Advisory
- seclists.org/fulldisclosure/2026/Aug/36nvdMailing List
- seclists.org/fulldisclosure/2026/Aug/37nvdBroken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
16- Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its DevicesCyber Security News · Sep 15, 2026
- Apple Updates Everything, (Mon, Sep 14th)SANS Internet Storm Center · Sep 14, 2026
- Hackers Actively Exploiting macOS’s Built-in Screen Sharing Service Vulnerability in the WildCyber Security News · Aug 19, 2026
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active ExploitationThe Hacker News · Aug 19, 2026
- CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple VulnerabilitiesSecurityWeek · Aug 19, 2026
- Apple: CVE-2026-65400 Zero-Day Added to CISA KEV Under Active ExploitationVypr Intelligence · Aug 18, 2026
- 17th August – Threat Intelligence ReportCheck Point Research · Aug 17, 2026
- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and MoreThe Hacker News · Aug 17, 2026
- Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominerHelp Net Security · Aug 17, 2026
- Update your Mac: Screen Sharing vulnerability exploited in the wildMalwarebytes Labs · Aug 17, 2026
- Recent macOS Screen Sharing Vulnerability Exploited in AttacksSecurityWeek · Aug 17, 2026
- Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero MinerThe Hacker News · Aug 15, 2026
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router BackdoorsThe Hacker News · Aug 10, 2026
- Microsoft, Apple Release Fresh Security UpdatesSecurityWeek · Aug 7, 2026
- August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?Help Net Security · Aug 7, 2026
- CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA Alerts