• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-65400: pre-auth improper authentication in Apple macOS

An attacker on the network can authenticate to macOS Screen Sharing without valid credentials, potentially gaining remote access to affected hosts. CVE-2026-65400 affects multiple macOS release lines; vulnerable releases are macOS Sonoma 14 before 14.8.9, macOS Sequoia 15 before 15.7.9, macOS Tahoe 26 before 26.6.1 and 26 before 26.7, and macOS Golden Gate 27 before 27. The vulnerability requires network access to the target host and does not require a valid account or user interaction to attempt exploitation.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.01219
CWE
CWE-287
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: CISA added this flaw to the Known Exploited Vulnerabilities catalog with a federal remediation deadline, and public exploit code exists, so prioritize patching or mitigations for internet-facing and high-value macOS hosts immediately.

What is CVE-2026-65400?

An attacker on the network can authenticate to macOS Screen Sharing without valid credentials, potentially gaining remote access to affected hosts. CVE-2026-65400 affects multiple macOS release lines; vulnerable releases are macOS Sonoma 14 before 14.8.9, macOS Sequoia 15 before 15.7.9, macOS Tahoe 26 before 26.6.1 and 26 before 26.7, and macOS Golden Gate 27 before 27. The vulnerability requires network access to the target host and does not require a valid account or user interaction to attempt exploitation. The weakness is classified as CWE-287 (Improper Authentication).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple macOS are affected?

BRANCHAFFECTEDFIXED
14.xbefore 14.8.914.8.9
15.xbefore 15.7.915.7.9
26.xbefore 26.6.126.6.1
26.xbefore 26.726.7
27.xbefore 2727

Is CVE-2026-65400 being exploited?

CISA added CVE-2026-65400 to the Known Exploited Vulnerabilities catalog on 2026-08-18, and U.S. federal agencies were required to remediate by 2026-08-21; public exploit code is also available.

How to fix CVE-2026-65400

  1. Install vendor fixes: upgrade to 14.8.9, 15.7.9, 26.6.1, 26.7, or 27 as applicable.
  2. If you cannot patch immediately, restrict network access to Screen Sharing services and block related ports at the perimeter.
  3. Monitor macOS hosts for unexpected Screen Sharing sessions and review authentication logs for anomalous connections.
  4. Follow Apple guidance and CISA KEV remediation instructions for prioritized deployment and forensics.

Frequently asked questions

Is CVE-2026-65400 being actively exploited?

CISA added CVE-2026-65400 to its Known Exploited Vulnerabilities catalog on 2026-08-18 and federal agencies had a remediation deadline of 2026-08-21; public exploit code is available.

Which macOS versions are affected by CVE-2026-65400?

macOS Sonoma 14 before 14.8.9, macOS Sequoia 15 before 15.7.9, macOS Tahoe 26 before 26.6.1 and 26 before 26.7, and macOS Golden Gate 27 before 27 are listed as affected.

Is there a patch for CVE-2026-65400?

Yes. Apple provided fixes; upgrade to 14.8.9, 15.7.9, 26.6.1, 26.7, or 27 as appropriate for your release line.

Does CVE-2026-65400 require authentication?

No. The vulnerability allows an attacker on the network to authenticate to macOS Screen Sharing without valid credentials, so exploitation does not require a legitimate account.

References