CVE-2026-65400 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-65400 | CVSS 9.8 (Critical) | Exploit: PoC available
What Is It
CVE-2026-65400 is an authentication bypass vulnerability in Apple macOS Screen Sharing that may allow a network-based attacker to authenticate without valid credentials.
Technical Detail
The issue results from insufficient state management in the Screen Sharing authentication process. An attacker with network access to a vulnerable Mac may be able to bypass normal credential validation and establish a Screen Sharing session. Successful exploitation could provide unauthorized remote access to the affected system through the Screen Sharing service.
Exploitation Status
A proof of concept is available. CISA has not listed this vulnerability in its Known Exploited Vulnerabilities catalog, and active exploitation in the wild has not been confirmed.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Apply Apple security updates with high priority. Update affected systems to macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, or macOS Tahoe 26.6.1, or later supported releases. Until updates can be deployed, disable Screen Sharing where it is not required and restrict access to Screen Sharing services to trusted administrative networks using host firewalls, network segmentation, or VPN-based access controls. Review Screen Sharing and remote-access logs for unexpected session activity, particularly successful connections from untrusted or unusual source addresses.