Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-65400

Published 2026-08-06
Updated 6 days ago
Vendor/s
Apple
Product/s
macOS
Version/s
14.0 > 14.8.9
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

Critical CVSS 9.8 authentication bypass in macOS Screen Sharing. Actively exploited. Update to macOS 15.7.9, 14.8.9, or 26.6.1 to secure your systems.

CPE

Apple logo
Apple
Product Version Start Version End (excl.) Status
macos 14.0 14.8.9 vulnerable
macos 15.0 15.7.9 vulnerable
macos 26.0 26.6.1 vulnerable

Related weakness (CWE)

CWE-287

Remediation plan

1

Apply official patches

Apple has released security updates specifically addressing this authentication state management issue. Organizations should immediately deploy the latest security updates provided by Apple for all managed macOS devices.

2

Update affected systems

Ensure all macOS devices are updated to at least macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, or macOS Tahoe 26.6.1. Inventory all assets to confirm no legacy versions (14.x or 15.x) remain unpatched.

3

Restrict access

Disable Screen Sharing and Remote Management services in System Settings if they are not required for business operations. If required, use a firewall or VPN to restrict access to port 5900 to known, trusted IP addresses only.

4

Monitor for exploitation

Audit system logs for 'screensharingd' activity and look for successful remote desktop sessions that do not correlate with known user logins. Monitor network traffic for unauthorized VNC connections originating from external or untrusted subnets.

Detection Guidance

"To detect potential exploitation of CVE-2026-65400, security teams should monitor macOS Unified Logs for 'screensharingd' processes and unusual authentication patterns. Specifically, look for successful Screen Sharing connections that bypass standard credential prompts. Network-level detection should focus on identifying inbound traffic on TCP port 5900 from unexpected sources. EDR tools can be configured to alert on unauthorized remote control sessions or the activation of Screen Sharing on sensitive endpoints."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management