CVE-2026-65400
Published Aug 6, 2026
Last updated 25 days ago
AI description
CVE-2026-65400 is an authentication bypass vulnerability affecting the Screen Sharing service in macOS. This flaw allows an attacker on the network to authenticate to Screen Sharing without needing valid credentials. The vulnerability stems from an issue with improved state management, specifically an error in the implementation of Secure Remote Password (SRP) authentication where the daemon's frame-length validator incorrectly returns a stale success status, leading to a connection being treated as authenticated when it is not. Successful exploitation of CVE-2026-65400 can grant unauthorized remote access to affected macOS systems. Security researchers have indicated that exploitation can extend beyond merely viewing a user's screen, potentially allowing an attacker to gain substantial control, including root access, over the compromised Mac. Apple released patches for this vulnerability on August 6, 2026, for macOS Sequoia (version 15.7.9), macOS Sonoma (version 14.8.9), and macOS Tahoe (version 26.6.1).
- Description
- An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
- Source
- product-security@apple.com
- NVD status
- Analyzed
- Products
- macos
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Apple macOS Improper Authentication Vulnerability
- Exploit added on
- Aug 18, 2026
- Exploit action due
- Aug 21, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-287
- Hype score
- Not currently trending
CISA added four flaws to KEV in a single day on Aug 18: Windows IKE (CVE-2026-33824), SharePoint (CVE-2026-55040), vCenter (CVE-2026-59310), macOS Screen Sharing (CVE-2026-65400). All four were patched before exploitation was confirmed. Patched is not the same as closed.
@InfosecDotWatch
29 Aug 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【技術解説】パッチを待つな、「悪用済み」から塞げ — 8月のCISA KEV追加 CISAが8月、悪用確認済みとしてmacOS画面共有(CVE-2026-65400)、SharePoint(CVE-2026-55040)、VMware vCenter(CVE-2026-59310)をKEVに追加。共通点は「認証の抜
@iss_kk_official
29 Aug 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Patch Now | August 26, 2026 Bringing these vulnerabilities to your attention. - Windows DHCP Client (CVE-2026-44815, CVSS 9.8) - Citrix NetScaler (CVE-2026-19490, CVSS 9.3) - macOS Screen Sharing (CVE-2026-65400, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG #CERTUGCC
@CERT_UG
26 Aug 2026
76 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
macOS Screen Sharing has a critical auth bypass under active exploitation: an attacker on your network can log in with no credentials at all (CVE-2026-65400, CVSS 9.8, KEV Aug 18). Fixed in Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1 — update, or disable Screen Sharing.
@SystemArch_AI
23 Aug 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft Patches Dozen-Plus Flaws, Apple Fixes Screen Sharing Bug CVE-2026-65400 https://t.co/SC0Q6wfUrX
@Anavem_
22 Aug 2026
82 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ CVE-2026-65400 : faille critique d'authentification macOS activement exploitée – CISA impose le patch avant le 21 août 2026. #zoneantimalware https://t.co/usjSoC81SN
@NicolasCoolman
22 Aug 2026
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA Warns - AI powered Zero-Day Alert! Microsoft Internet Key Exchange (IKE) Extensions (`CVE-2026-33824`) — CVSS 9.8 Broadcom VMware vCenter (`CVE-2026-59310`) — CVSS 9.8 Apple macOS Screen Sharing (`CVE-2026-65400`) — CVSS 9.8 Microsoft SharePoint Server (`CVE-2026-550
@HOCupdate
21 Aug 2026
382 Impressions
2 Retweets
2 Likes
1 Bookmark
0 Replies
0 Quotes
Four Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824
@BlackfireLu
20 Aug 2026
71 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: EGE-GH-bnhF7il ( CVE-2020-14882 ) EGE-GH-seDznkg ( CVE-2026-65400 ) EGE-GH-voHnlXt ( CVE-2026-15748 ) EGE-GH-UkSlg0M ( CVE-2026-19598 ) EGE-GH-IxgnwCb ( CVE-2025-62593 ) ..🧵👇
@exploitgrid
19 Aug 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Four Critical Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824 Reported attacks include Monero mining, persistent access, and Babuk-derived ransomware. Read: https://t.co/Zs
@TheHackersNews
19 Aug 2026
48061 Impressions
90 Retweets
317 Likes
91 Bookmarks
4 Replies
3 Quotes
CVE-2026-65400 — Apple macOS Improper Authentication Vulnerability https://t.co/Cb54o7TgjW #cve #apple #cve202665400
@Npj8448
19 Aug 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-65400: Apple macOS Screen Sharing Authentication Bypass — Detection an… "On August 18, 2026, CISA added CVE-2026-65400 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/rH4LFm2VxW #CyberSecurity #ThreatIntel #cve202665400 #critical
@SecurityAr58409
19 Aug 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - CVE-2026-33824 (Windows) - CVE-2026-55040 (Sharepoint) - CVE-2026-59310 (vCenter) - CVE-2026-65400 (macOS) 対処期限は3日
@__kokumoto
18 Aug 2026
634 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
Legacy exposure keeps paying off for attackers. macOS Screen Sharing CVE-2026-65400 exploited to gain roo… CVE-2026-65400 is being exploited against internet-exposed macOS Screen Sharing systems to… 🔗 Read → https://t.co/f2TXK97EBb
@fynn_JourX
18 Aug 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
𝗧𝗵𝗲 𝗹𝗮𝘁𝗲𝘀𝘁 𝗣𝗵𝗼𝗻𝗲𝘀 & 𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲 𝗡𝗲𝘄𝘀 ⬆️ Updates Apple Patches 122 Flaws including macOS Screen Sharing Flaw (CVE-2026-65400) Apple fixed 122 CVEs in iOS 18.7.10, 29 in iOS 26.6.1 and 28 in macOS
@francoboca
18 Aug 2026
126 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛑 macOS Screen Sharing CVE-2026-65400 exploited to gain root and deploy M… CVE-2026-65400 is being exploited against internet-exposed macOS Screen Sharing systems to… 🔗 Details → https://t.co/IHMal97LT9
@lucasverdan
18 Aug 2026
57 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ช่องโหว่ macOS Screen Sharing (CVE-2026-65400) โดน CISA ปรับความรุนแรงขึ้นเป็น 9.8/10 หลัง NCSC เนเธอร์แลนด์ยืนยันแฮ็กเกอร์เจาะเครื่
@BitcoinAddictTH
17 Aug 2026
431 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚠️SAP Commerce Cloudの脆弱性、修正から3日後に悪用試行始まる:CVE-2026-58231 🪙macOS画面共有機能の脆弱性を攻撃者が悪用し、モネロマイナーを展開:CVE-2026-65400 🚨GeoServerにおけるパッチ未提供のゼロデイをハ
@MachinaRecord
17 Aug 2026
106 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 Un CVE crítico está siendo explotado a nivel global: macOS Screen Sharing Flaw permite a hackers desplegar mineros de Monero en Macs con el puerto 5900 expuesto en línea. La vulnerabilidad CVE-2026-65400, con una puntuación CVSS de 9.8, está siendo activamente explotad
@BotBauR
16 Aug 2026
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 ALERTA CRÍTICA 🚨 Una vulnerabilidad en macOS permite a atacantes instalar mineros de Monero. La CVE-2026-65400, calificada con un 7.1 sobre 10, explota el uso compartido de pantalla sin credenciales. Ataques activos han sido confirmados. El puerto 5900 está expuesto.
@DiarioBitcoin
16 Aug 2026
788 Impressions
1 Retweet
1 Like
1 Bookmark
1 Reply
0 Quotes
Critical macOS Screen Sharing Bug (CVE-2026-65400) | Exploitation to Install Monero Miners.. https://t.co/gTAitzQl30 #infosec #security https://t.co/Qm2vi3HWBj
@HOCupdate
15 Aug 2026
353 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
TRC analysis shows attackers exploiting CVE-2026-65400 to bypass macOS Screen Sharing authentication entirely. Once inside, they escalated to root privileges and deployed Monero miners across compromised systems. Runtime segmentation could have limited the blast radius of this
@aviatrixtrc
15 Aug 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-65400 Lets Attackers Root Your Mac Via Screen Sharing > Dutch NCSC warns attackers are actively exploiting CVE-2026-65400 to gain root access on Macs and install a Monero miner via exposed port 5900 > attackers have already rooted multiple Macs exposed on port 590
@0J0BIT
14 Aug 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-59310 and CVE-2026-65400 are under active exploitation, with CVSS scores of 9.8 and 7.1 respectively. Patch immediately to protect against critical directory traversal and authentication vulnerabilities #ThreatIntel #CyberSecurity https://t.co/h713XbjpvW
@Npj8448
13 Aug 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical macOS Screen Sharing Flaw Enables Pre-Auth RCE and Root File Access https://t.co/TZW9PJsg1T "CVE-2026-65400 follows closely on the heels of CVE-2026-43760, a separate Screen Sharing bug disclosed in late July."
@catnap707
9 Aug 2026
215 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "343D2ED2-0928-434D-9D9E-968A6365DDFE",
"versionEndExcluding": "14.8.9",
"versionStartIncluding": "14.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E0FAFB32-637E-4BE3-8A5D-ABB145B1E28B",
"versionEndExcluding": "15.7.9",
"versionStartIncluding": "15.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "31BB841D-2EFD-42A5-9387-685A27D3094E",
"versionEndExcluding": "26.6.1",
"versionStartIncluding": "26.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]