Critical CVSS 9.8 authentication bypass in macOS Screen Sharing. Actively exploited. Update to macOS 15.7.9, 14.8.9, or 26.6.1 to secure your systems.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| macos | 14.0 | 14.8.9 | vulnerable |
| macos | 15.0 | 15.7.9 | vulnerable |
| macos | 26.0 | 26.6.1 | vulnerable |
Apple has released security updates specifically addressing this authentication state management issue. Organizations should immediately deploy the latest security updates provided by Apple for all managed macOS devices.
Ensure all macOS devices are updated to at least macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, or macOS Tahoe 26.6.1. Inventory all assets to confirm no legacy versions (14.x or 15.x) remain unpatched.
Disable Screen Sharing and Remote Management services in System Settings if they are not required for business operations. If required, use a firewall or VPN to restrict access to port 5900 to known, trusted IP addresses only.
Audit system logs for 'screensharingd' activity and look for successful remote desktop sessions that do not correlate with known user logins. Monitor network traffic for unauthorized VNC connections originating from external or untrusted subnets.
"To detect potential exploitation of CVE-2026-65400, security teams should monitor macOS Unified Logs for 'screensharingd' processes and unusual authentication patterns. Specifically, look for successful Screen Sharing connections that bypass standard credential prompts. Network-level detection should focus on identifying inbound traffic on TCP port 5900 from unexpected sources. EDR tools can be configured to alert on unauthorized remote control sessions or the activation of Screen Sharing on sensitive endpoints."
Experience superior visibility and a simpler approach to cyber risk management