CVE-2026-65400
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Aug 18, 2026
- US federal agencies must remediate it by Aug 21, 2026 (BOD 22-01)
- Attacked on the day of disclosure
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Source: CISA KEV · Sep 8, 2026 Sep 3, 2026 Sep 1, 2026 Aug 18, 2026 Aug 17, 2026 Aug 15, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| apple | macos | < 14.8.9 |
Related articles
VulnerabilitiesMicrosoft and Apple Fix Critical Flaws in Cloud Services, Directories, and Screen Sharing
Microsoft and Apple release critical patches for Azure, Active Directory, and Screen Sharing vulnerabilities, addressing high-severity flaws.
VulnerabilitiesmacOS Screen Sharing Actively Exploited: Monero Miner Installed on Exposed Systems
The Netherlands’ National Cyber Security Centre NCSC has reported active exploitation of CVE-2026-65400 , a vulnerability in macOS Screen Sharing , the
VulnerabilitiesFour Critical Vulnerabilities Exploited Against macOS, SharePoint, VMware vCenter, and Windows
CISA has added four actively exploited critical vulnerabilities to its Known Exploited Vulnerabilities KEV catalog. The flaws affect Apple macOS,
VulnerabilitiesCybersecurity, August 20 Threats: From Gogs to macOS, Signed Drivers, and Targeted Campaigns
Explore critical cybersecurity threats from August 20, including Gogs RCE, macOS vulnerabilities, and abuse of signed drivers.
VulnerabilitiesGitea Under Attack: Critical RCE Exploited for Cryptojacking, CISA Mandates Patch by August 28
Critical RCE in Gitea (CVE-2026-60004) is being exploited for cryptojacking. CISA requires federal agencies to patch by August 28, 2026.
VulnerabilitiesExploited Cisco ISE Flaw Leads a Wave of Attacks on Trusted Software Channels
Active exploitation of a critical Cisco ISE flaw highlights attacks through trusted software channels, Orkes, Discourse, libheif and AI plugins.
This product uses the NVD API but is not endorsed or certified by the NVD.