CVE-2026-65400
Known exploited · CISA KEV
CVSS 7.1 HIGH: an authentication issue was addressed with improved state management.
CISA federal remediation date Aug 21
Vulnerabilities & Exploits
The break is in Screen Sharing’s login logic, not in macOS itself. If the service loses track of auth state, a network request can be accepted as already vetted, so changing passwords does not fix the weakness on its own.
Apple fixed CVE-2026-65400 in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. NCSC-NL says the flaw let remote attackers gain access without valid credentials because state management during authentication was insufficient, and Apple tightened that validation so only legitimate logins are accepted.
3 sources · Aug 7
Known exploited · CISA KEV
CVSS 7.1 HIGH: an authentication issue was addressed with improved state management.
CISA federal remediation date Aug 21
CSIRT Italia / ACN
Aggiornamenti di sicurezza Apple
Aggiornamenti di sicurezza Apple sanano una vulnerabilità con gravità "alta", presente in macOS Sonoma, macOS Sequoia e macOS Tahoe.
originalNCSC-NL Advisories
Kwetsbaarheid verholpen in macOS Screen Sharing door Apple Revisies
Apple heeft een kwetsbaarheid verholpen in de Screen Sharing feature van macOS versies Sequoia 15.7.9, Sonoma 14.8.9 en Tahoe 26.6.1.
originalHuntress Blog
From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOS | Huntress
Apple’s latest macOS update addresses two vulnerabilities in its Screen Sharing server, including one that enables pre-authenticated remote code execution.
originalPart of the PlainSec briefing for 2026-08-08
Every edition of this story: Screen Sharing Bypass Lets Attackers Log In Without Credentials