CVE-2026-65400
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
A flaw in macOS Screen Sharing allows an attacker on the same network to gain access without entering a password or valid credentials. This is critical because it can lead to unauthorized remote control of your computer.
An authentication state management vulnerability in macOS Screen Sharing (CVE-2026-65400, CWE-287) permits unauthenticated remote access over the network. The attack vector requires network proximity; an attacker can bypass credential validation to establish a Screen Sharing session, potentially gaining full remote control of the affected system.