CVE-2026-65400

Published Aug 6, 2026

Last updated 25 days ago

Exploit knownCVSS critical 9.8
Docker
Zero-day
Supply chain

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-65400 is an authentication bypass vulnerability affecting the Screen Sharing service in macOS. This flaw allows an attacker on the network to authenticate to Screen Sharing without needing valid credentials. The vulnerability stems from an issue with improved state management, specifically an error in the implementation of Secure Remote Password (SRP) authentication where the daemon's frame-length validator incorrectly returns a stale success status, leading to a connection being treated as authenticated when it is not. Successful exploitation of CVE-2026-65400 can grant unauthorized remote access to affected macOS systems. Security researchers have indicated that exploitation can extend beyond merely viewing a user's screen, potentially allowing an attacker to gain substantial control, including root access, over the compromised Mac. Apple released patches for this vulnerability on August 6, 2026, for macOS Sequoia (version 15.7.9), macOS Sonoma (version 14.8.9), and macOS Tahoe (version 26.6.1).

Description
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Source
product-security@apple.com
NVD status
Analyzed
Products
macos

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Apple macOS Improper Authentication Vulnerability
Exploit added on
Aug 18, 2026
Exploit action due
Aug 21, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-287

Social media

Hype score
Not currently trending
  1. CISA added four flaws to KEV in a single day on Aug 18: Windows IKE (CVE-2026-33824), SharePoint (CVE-2026-55040), vCenter (CVE-2026-59310), macOS Screen Sharing (CVE-2026-65400). All four were patched before exploitation was confirmed. Patched is not the same as closed.

    @InfosecDotWatch

    29 Aug 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 【技術解説】パッチを待つな、「悪用済み」から塞げ — 8月のCISA KEV追加 CISAが8月、悪用確認済みとしてmacOS画面共有(CVE-2026-65400)、SharePoint(CVE-2026-55040)、VMware vCenter(CVE-2026-59310)をKEVに追加。共通点は「認証の抜

    @iss_kk_official

    29 Aug 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 Patch Now | August 26, 2026 Bringing these vulnerabilities to your attention. - Windows DHCP Client (CVE-2026-44815, CVSS 9.8) - Citrix NetScaler (CVE-2026-19490, CVSS 9.3) - macOS Screen Sharing (CVE-2026-65400, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG #CERTUGCC

    @CERT_UG

    26 Aug 2026

    76 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. macOS Screen Sharing has a critical auth bypass under active exploitation: an attacker on your network can log in with no credentials at all (CVE-2026-65400, CVSS 9.8, KEV Aug 18). Fixed in Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1 — update, or disable Screen Sharing.

    @SystemArch_AI

    23 Aug 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Microsoft Patches Dozen-Plus Flaws, Apple Fixes Screen Sharing Bug CVE-2026-65400 https://t.co/SC0Q6wfUrX

    @Anavem_

    22 Aug 2026

    82 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ⚠️ CVE-2026-65400 : faille critique d'authentification macOS activement exploitée – CISA impose le patch avant le 21 août 2026. #zoneantimalware https://t.co/usjSoC81SN

    @NicolasCoolman

    22 Aug 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CISA Warns - AI powered Zero-Day Alert! Microsoft Internet Key Exchange (IKE) Extensions (`CVE-2026-33824`) — CVSS 9.8 Broadcom VMware vCenter (`CVE-2026-59310`) — CVSS 9.8 Apple macOS Screen Sharing (`CVE-2026-65400`) — CVSS 9.8 Microsoft SharePoint Server (`CVE-2026-550

    @HOCupdate

    21 Aug 2026

    382 Impressions

    2 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  8. Four Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824

    @BlackfireLu

    20 Aug 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: EGE-GH-bnhF7il ( CVE-2020-14882 ) EGE-GH-seDznkg ( CVE-2026-65400 ) EGE-GH-voHnlXt ( CVE-2026-15748 ) EGE-GH-UkSlg0M ( CVE-2026-19598 ) EGE-GH-IxgnwCb ( CVE-2025-62593 ) ..🧵👇

    @exploitgrid

    19 Aug 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. 🚨 Four Critical Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824 Reported attacks include Monero mining, persistent access, and Babuk-derived ransomware. Read: https://t.co/Zs

    @TheHackersNews

    19 Aug 2026

    48061 Impressions

    90 Retweets

    317 Likes

    91 Bookmarks

    4 Replies

    3 Quotes

  11. CVE-2026-65400 — Apple macOS Improper Authentication Vulnerability https://t.co/Cb54o7TgjW #cve #apple #cve202665400

    @Npj8448

    19 Aug 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🔒 #CyberSecurity CVE-2026-65400: Apple macOS Screen Sharing Authentication Bypass — Detection an… "On August 18, 2026, CISA added CVE-2026-65400 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/rH4LFm2VxW #CyberSecurity #ThreatIntel #cve202665400 #critical

    @SecurityAr58409

    19 Aug 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - CVE-2026-33824 (Windows) - CVE-2026-55040 (Sharepoint) - CVE-2026-59310 (vCenter) - CVE-2026-65400 (macOS) 対処期限は3日

    @__kokumoto

    18 Aug 2026

    634 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Legacy exposure keeps paying off for attackers. macOS Screen Sharing CVE-2026-65400 exploited to gain roo… CVE-2026-65400 is being exploited against internet-exposed macOS Screen Sharing systems to… 🔗 Read → https://t.co/f2TXK97EBb

    @fynn_JourX

    18 Aug 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 𝗧𝗵𝗲 𝗹𝗮𝘁𝗲𝘀𝘁 𝗣𝗵𝗼𝗻𝗲𝘀 & 𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲 𝗡𝗲𝘄𝘀 ⬆️ Updates Apple Patches 122 Flaws including macOS Screen Sharing Flaw (CVE-2026-65400) Apple fixed 122 CVEs in iOS 18.7.10, 29 in iOS 26.6.1 and 28 in macOS

    @francoboca

    18 Aug 2026

    126 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🛑 macOS Screen Sharing CVE-2026-65400 exploited to gain root and deploy M… CVE-2026-65400 is being exploited against internet-exposed macOS Screen Sharing systems to… 🔗 Details → https://t.co/IHMal97LT9

    @lucasverdan

    18 Aug 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. ช่องโหว่ macOS Screen Sharing (CVE-2026-65400) โดน CISA ปรับความรุนแรงขึ้นเป็น 9.8/10 หลัง NCSC เนเธอร์แลนด์ยืนยันแฮ็กเกอร์เจาะเครื่

    @BitcoinAddictTH

    17 Aug 2026

    431 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  18. ⚠️SAP Commerce Cloudの脆弱性、修正から3日後に悪用試行始まる:CVE-2026-58231 🪙macOS画面共有機能の脆弱性を攻撃者が悪用し、モネロマイナーを展開:CVE-2026-65400 🚨GeoServerにおけるパッチ未提供のゼロデイをハ

    @MachinaRecord

    17 Aug 2026

    106 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🔴 Un CVE crítico está siendo explotado a nivel global: macOS Screen Sharing Flaw permite a hackers desplegar mineros de Monero en Macs con el puerto 5900 expuesto en línea. La vulnerabilidad CVE-2026-65400, con una puntuación CVSS de 9.8, está siendo activamente explotad

    @BotBauR

    16 Aug 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨 ALERTA CRÍTICA 🚨 Una vulnerabilidad en macOS permite a atacantes instalar mineros de Monero. La CVE-2026-65400, calificada con un 7.1 sobre 10, explota el uso compartido de pantalla sin credenciales. Ataques activos han sido confirmados. El puerto 5900 está expuesto.

    @DiarioBitcoin

    16 Aug 2026

    788 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  21. Critical macOS Screen Sharing Bug (CVE-2026-65400) | Exploitation to Install Monero Miners.. https://t.co/gTAitzQl30 #infosec #security https://t.co/Qm2vi3HWBj

    @HOCupdate

    15 Aug 2026

    353 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  22. TRC analysis shows attackers exploiting CVE-2026-65400 to bypass macOS Screen Sharing authentication entirely. Once inside, they escalated to root privileges and deployed Monero miners across compromised systems. Runtime segmentation could have limited the blast radius of this

    @aviatrixtrc

    15 Aug 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. CVE-2026-65400 Lets Attackers Root Your Mac Via Screen Sharing > Dutch NCSC warns attackers are actively exploiting CVE-2026-65400 to gain root access on Macs and install a Monero miner via exposed port 5900 > attackers have already rooted multiple Macs exposed on port 590

    @0J0BIT

    14 Aug 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨 CVE-2026-59310 and CVE-2026-65400 are under active exploitation, with CVSS scores of 9.8 and 7.1 respectively. Patch immediately to protect against critical directory traversal and authentication vulnerabilities #ThreatIntel #CyberSecurity https://t.co/h713XbjpvW

    @Npj8448

    13 Aug 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. Critical macOS Screen Sharing Flaw Enables Pre-Auth RCE and Root File Access https://t.co/TZW9PJsg1T "CVE-2026-65400 follows closely on the heels of CVE-2026-43760, a separate Screen Sharing bug disclosed in late July."

    @catnap707

    9 Aug 2026

    215 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations