Apple macOS Screen Sharing authentication bypass (CVE-2026-65400), exploited
Apple's 6 August 2026 security content for macOS Tahoe 26.6.1 (and matching Sequoia/Sonoma notes) says an authentication issue in Screen Sharing was addressed with improved state management. Impact: an attacker on the network may be able to authenticate to Screen Sharing without valid credentials. Fixed in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. CISA added the CVE to KEV on 18 August 2026 (due 21 August for federal agencies under BOD 26-04) and CISA-ADP rates CVSS 3.1 9.8. Apply the Apple builds above; if Screen Sharing is not required, disable it and keep TCP 5900 off the public internet. Distinct from the 17 August iOS/macOS content card already on this desk.
- Product
- Apple macOS Screen Sharing (screensharingd)
- Versions
- macOS Tahoe before 26.6.1; Sequoia before 15.7.9; Sonoma before 14.8.9
- CVSS
- (CVSS 3.1, CISA-ADP)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- macOS Tahoe 26.6.1; Sequoia 15.7.9; Sonoma 14.8.9
Primary: Apple: macOS Tahoe 26.6.1 security content · Vendor: Apple Support (148170) · CVE: CVE-2026-65400 · CISA KEV addition notice (18 Aug 2026)
