Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-65400: macOS lets network attacker join Screen Sharing

CVE-2026-65400 · published 1 month ago · actively exploited
Summary

The macOS operating system can let someone on the same network connect to the built‑in Screen Sharing feature without needing a username or password. This could give the attacker visual access to the computer and the ability to control it. Apply the latest macOS update or disable Screen Sharing until the patch is installed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
apple macos < 14.8.9
>= 14.0, < 14.8.9
>= 15.0, < 15.7.9
>= 26.0, < 26.6.1
Original advisory text
Apple macOS Improper Authentication Vulnerability
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
Fix within
Internet-facing 3 days
and check for signs of compromise
Internal 3 days
and check for signs of compromise
  • Known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
2% chance of attack within 30 days
Type
CWE-287Improper Authentication
Timeline
Published6 Aug 2026
Updated1 Oct 2026
First seen6 Aug 2026
Sources
CVE-2026-65400 · MITRE
CVE-2026-65400 · CISA KEV
Track software like this
Free during beta