Authentication Vulnerability in macOS Products by Apple
CVE-2026-65400
Key Information:
Badges
What is CVE-2026-65400?
CVE-2026-65400 is an authentication vulnerability identified in Apple's macOS products, specifically impacting Screen Sharing functionalities. The flaw arises from inadequate state management during the authentication process, permitting unauthorized individuals on the network to gain access without valid credentials. This vulnerability is particularly concerning for organizations utilizing macOS systems, as it can facilitate unauthorized control over user sessions, posing significant security risks. The issue has been remediated in recent updates, namely macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, and macOS Tahoe 26.6.1.
Potential impact of CVE-2026-65400
-
Unauthorized Access: This vulnerability potentially allows attackers to bypass authentication requirements, leading to unauthorized access to sensitive user sessions and data. Such access could result in the compromise of confidential information and systems.
-
Data Breach Risks: With unauthorized access, there is a heightened risk of data breaches, where sensitive organizational data could be exposed, stolen, or manipulated, leading to substantial reputational and financial damage.
-
Network Security Compromise: The ability for attackers to authenticate without proper credentials weakens overall network security, potentially leading to further exploitation of connected systems or services, as malicious actors could pivot from the compromised sessions to target additional assets within the network.
CISA has reported CVE-2026-65400
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-65400 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
macOS 0 < 14.8.9
macOS 0 < 15.7.9
macOS 0 < 26.6.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Apple just patched a critical macOS flaw that let hackers break in without a password
The Netherlands' National Cyber Security Centre (NCSC-NL) recently published an alarming security advisory about the new macOS flaw. It describes a vulnerability tied to an improper authentication...
1 week ago
macOS Screen Sharing Flaw (CVE-2026-65400) Actively Exploited for Crypto Mining
A vulnerability in macOS screen sharing (CVE-2026-65400) enables remote code execution without user interaction, allowing attackers to install Monero cryptocurrency miners on Apple systems. The flaw, stemming from improper input validation, has been actively exploited in enterprise environments. App...
2 weeks ago
Apple's Screen Sharing Flaw Opens Macs to Root Takeovers and Crypto Mining
A macOS Screen Sharing authentication bypass (CVE-2026-65400) lets attackers gain root without credentials. Apple patched it in August updates, but criminals already use it to install Monero miners on exposed systems. Enterprises must update immediately and lock down port 5900. The flaw's severity j...
2 weeks ago
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 💰
Used in Ransomware
- 🦅
CISA Reported
- 🥇
Vulnerability reached the number 1 worldwide trending spot
- 📈
Vulnerability started trending
- 👾
Exploit known to exist
- 📰
First article discovered by Webpronews
Vulnerability published
Vulnerability Reserved