Vulnerability
Published 2026-08-06
Verified 2026-09-19

Apple macOS Screen Sharing authentication bypass (CVE-2026-65400), exploited

Apple's 6 August 2026 security content for macOS Tahoe 26.6.1 (and matching Sequoia/Sonoma notes) says an authentication issue in Screen Sharing was addressed with improved state management. Impact: an attacker on the network may be able to authenticate to Screen Sharing without valid credentials. Fixed in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. CISA added the CVE to KEV on 18 August 2026 (due 21 August for federal agencies under BOD 26-04) and CISA-ADP rates CVSS 3.1 9.8. Apply the Apple builds above; if Screen Sharing is not required, disable it and keep TCP 5900 off the public internet. Distinct from the 17 August iOS/macOS content card already on this desk.

Product
Apple macOS Screen Sharing (screensharingd)
Versions
macOS Tahoe before 26.6.1; Sequoia before 15.7.9; Sonoma before 14.8.9
CVSS
(CVSS 3.1, CISA-ADP)
Exploited in Australia?
unknown
Patch to
macOS Tahoe 26.6.1; Sequoia 15.7.9; Sonoma 14.8.9

Primary: Apple: macOS Tahoe 26.6.1 security content · Vendor: Apple Support (148170) · CVE: CVE-2026-65400 · CISA KEV addition notice (18 Aug 2026)

vulnerabilities identity