Skip to main content

Exploitation of Critical Authentication Bypass Vulnerability in macOS Screen Sharing

CVE-2026-65400 could allow unauthenticated network attackers to access macOS Screen Sharing services

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

CVE-2026-65400 could allow unauthenticated network attackers to access macOS Screen Sharing services


Threat details

Exploitation in the wild of CVE-2026-65400

Active exploitation of CVE-2026-65400 has been reported, with compromised systems observed hosting cryptocurrency mining malware after successful exploitation. Public proof-of-concept exploit code is available and the US Cybersecurity and Infrastructure Security Agency's (CISA) has added it to the Known Exploited Vulnerabilities (KEV) catalog.

NHS England's National CSOC assesses continued exploitation as likely.


Introduction

Active exploitation of critical authentication bypass vulnerability CVE-2026-65400 has been reported. Successful exploitation could allow a network-based attacker to authenticate to Screen Sharing services without valid credentials, potentially leading to unauthorised access to affected systems.

Apple released security updates to address this critical vulnerability in macOS Screen Sharing on 6 August 2026. 

  • CVE-2026-65400 - Improper Authentication - CVSSv3.1 score: 9.8

Remediation advice

Affected organisations are encouraged to review the Apple security advisories below and apply the relevant update as soon as possible.


Remediation steps

Type Step
Patch

macOS Sequoia 15.7.9


https://support.apple.com/en-us/148171
Patch

macOS Sonoma 14.8.9


https://support.apple.com/en-us/148172
Patch

macOS Tahoe 26.6.1


https://support.apple.com/en-us/148170


Last edited: 24 August 2026 3:30 pm