Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-65400: macOS lets network attacker join Screen Sharing
CVE-2026-65400 · published 1 month ago · actively exploited
Summary
The macOS operating system can let someone on the same network connect to the built‑in Screen Sharing feature without needing a username or password. This could give the attacker visual access to the computer and the ability to control it. Apply the latest macOS update or disable Screen Sharing until the patch is installed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apple | macos |
< 14.8.9 >= 14.0, < 14.8.9 >= 15.0, < 15.7.9 >= 26.0, < 26.6.1 |
Original advisory text
Apple macOS Improper Authentication Vulnerability
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
References
- https://support.apple.com/en-us/148170 Release Notes Vendor Advisory
- https://support.apple.com/en-us/148171 Release Notes Vendor Advisory
- http://seclists.org/fulldisclosure/2026/Aug/36 Mailing List
- https://support.apple.com/en-us/149035 Release Notes Vendor Advisory
- https://support.apple.com/en-us/149042 Release Notes Vendor Advisory
- https://support.apple.com/en-us/148172 Release Notes Vendor Advisory
- http://seclists.org/fulldisclosure/2026/Aug/37 Broken Link
- https://advisories.ncsc.nl/2026/ncsc-2026-0280.html Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-... US Government Resource
Internet-facing
3 days
and check for signs of compromise
Internal
3 days
and check for signs of compromise
- Known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
2%
chance of attack within 30 days
Type
CWE-287Improper Authentication
Timeline
Published6 Aug 2026
Updated1 Oct 2026
First seen6 Aug 2026
Track software like this
Free during beta