SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-65400 2026-08-18

CVE-2026-65400: Critical macOS Screen Sharing Authentication Bypass Added to CISA KEV

"Apple has patched a critical improper authentication flaw (CVSS 9.8) that, per Apple's advisory, may allow an attacker on the network to authenticate to macOS Screen Sharing without valid credentials, and CISA added it…"

Apple has patched a critical improper authentication flaw (CVSS 9.8) that, per Apple's advisory, may allow an attacker on the network to authenticate to macOS Screen Sharing without valid credentials, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-18.

What Is It

CVE-2026-65400 is an authentication issue in macOS that Apple describes as "addressed with improved state management." Per Apple's advisory, an attacker on the network may be able to authenticate to Screen Sharing without valid credentials. It is classified as CWE-287 (Improper Authentication).

The CVSS v3.1 base score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, no user interaction, with high confidentiality, integrity, and availability impact.

Why It Matters

CISA added the CVE to the KEV catalog on 2026-08-18, and the SSVC decision data from the CISA Coordinator lists exploitation as active, automatable as yes, and technical impact as total. Known ransomware campaign use is listed as Unknown.

The combination of an unauthenticated network path into Screen Sharing and a "total" technical impact suggests that a successful attacker could obtain interactive access to the host, though neither Apple nor CISA has published details of post-exploitation behavior. The automatable rating indicates the attack can be scripted at scale.

What's Vulnerable

Apple macOS, in the following version ranges:

Patch Status

Fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, and macOS Tahoe 26.6.1.

CISA's required action: apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 "Prioritizing Security Updates Based on Risk" guidance and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. The KEV due date is 2026-08-21: three days after listing.

Sources