Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

CVE-2026-65400 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-65400 | CVSS 9.8 (Critical) | Exploit: PoC available

What Is It

CVE-2026-65400 is an authentication bypass vulnerability in Apple macOS Screen Sharing that may allow a network-based attacker to authenticate without valid credentials.

Technical Detail

The issue results from insufficient state management in the Screen Sharing authentication process. An attacker with network access to a vulnerable Mac may be able to bypass normal credential validation and establish a Screen Sharing session. Successful exploitation could provide unauthorized remote access to the affected system through the Screen Sharing service.

Exploitation Status

A proof of concept is available. CISA has not listed this vulnerability in its Known Exploited Vulnerabilities catalog, and active exploitation in the wild has not been confirmed.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Apply Apple security updates with high priority. Update affected systems to macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, or macOS Tahoe 26.6.1, or later supported releases. Until updates can be deployed, disable Screen Sharing where it is not required and restrict access to Screen Sharing services to trusted administrative networks using host firewalls, network segmentation, or VPN-based access controls. Review Screen Sharing and remote-access logs for unexpected session activity, particularly successful connections from untrusted or unusual source addresses.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →