CVE-2026-65400: Apple macOS Improper Authentication Vulnerability
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
CSIRTS triage
- What
- macOS contains an improper authentication vulnerability allowing unauthenticated access to Screen Sharing.
- Who is affected
- macOS systems with Screen Sharing enabled and accessible on the network.
- Urgency
- Critical; actively exploited vulnerability undermining network authentication controls.
- Action
- Apply the latest macOS security update immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch macOS
Get an email when a new macOS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-65400
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-65400Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 52% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-65400 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedApple security advisory (AV26-823) – Update 1cccs
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- high[NEW] [medium] Apple macOS (Sonoma, Sequoia and Tahoe): Vulnerability enables security feature bypasscert-bund
- unknownexploitedNCSC-2026-0280 [1.01] [M/H] Vulnerability patched in macOS Screen Sharing by Applencsc-nl
- unknownNCSC-2026-0280 [1.00] [M/H] Vulnerability fixed in macOS Screen Sharing by Applencsc-nl
- unknownexploitedApple macOS Security Restriction Bypass Vulnerabilityhkcert
- unknownVulnerability in Apple macOS (August 07, 2026)cert-fr-avis
- highCVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in m…nvd
More from CISA Known Exploited Vulnerabilities
- criticalCVE-2026-64849: MLflow Server-Side Request Forgery Vulnerability2026-08-19
- criticalCVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability2026-08-18
- criticalCVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability2026-08-18
- criticalCVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability2026-08-18
- criticalCVE-2025-62593: Ray-Project Ray Code Injection Vulnerability2026-08-17