← back
CVE-2026-65400criticalunder attackCWE-287

CVE-2026-65400

78Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 9.8epss 9.9%
from disclosure to weapon12 days
Published on NVDAug 6
1st PoC+12d
CISA KEV+12d
exploitation probability
9.9%top 5% of all CVEs
observed exploitation
yesCISA + VulnCheck
5 public exploit(s)
Action required by CISAfederal deadline: 2026-08-21

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

A flaw in macOS Screen Sharing allows an attacker on the same network to gain access without entering a password or valid credentials. This is critical because it can lead to unauthorized remote control of your computer.

Technical detail

An authentication state management vulnerability in macOS Screen Sharing (CVE-2026-65400, CWE-287) permits unauthenticated remote access over the network. The attack vector requires network proximity; an attacker can bypass credential validation to establish a Screen Sharing session, potentially gaining full remote control of the affected system.

Summary generated and translated by AI from the official description.
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Apple · macOS
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.