CVE-2026-65400
Apple macOS Improper Authentication Vulnerability
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Deadline for federal agencies: 2026-08-21.
15 articles across 9 outlets · first covered Aug 7, 2026 · latest Sep 16, 2026
Coverage timeline
-
Apple Patches 273 Flaws as Screen Sharing Bug Faces Active Attackswww.thezdi.com · Sep 16, 2026
-
Apple Patches Record 261 Flaws Across New Operating Systemsisc.sans.edu · Sep 14, 2026
-
Telegram seeks .gram domain as critical zero day exploits surgesecurityonline.info · Aug 19, 2026
-
Urgent Patches Address Flaws in Microsoft, Apple, IBM Db2securityonline.info · Aug 19, 2026
-
Google patches Android ContactsProvider2 SQLi high severity bugsecurityonline.info · Aug 19, 2026
-
CISA warns of active exploits in Microsoft, VMware, Apple bugswww.securityweek.com · Aug 19, 2026
-
-
CISA KEV Adds Four Exploited Flaws in SharePoint, vCentersecurityonline.info · Aug 19, 2026
-
CISA flags macOS Screen Sharing bug CVE-2026-65400 as exploitedwww.cisa.gov · Aug 19, 2026
-
CISA Adds CVE-2026-65400 to Known Exploited Vulnerabilities Cataloguecisa.gov · Aug 18, 2026
-
Update your Mac: Screen Sharing vulnerability exploited in the wildwww.malwarebytes.com · Aug 17, 2026
-
Apple fixes macOS Screen Sharing bug exploited for crypto miningwww.securityweek.com · Aug 17, 2026
-
Hackers exploit CVE-2026-65400 to mine Monero on macOSsecurityaffairs.com · Aug 15, 2026
-
Apple patches CVE-2026-65400 macOS flaw after crypto miner attacksarstechnica.com · Aug 14, 2026
-
Microsoft, Apple issue patches for critical RCE and auth bypasswww.securityweek.com · Aug 7, 2026