LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-65400: Apple macOS Improper Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 18, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 21, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-65400 to its Known Exploited Vulnerabilities catalog on Aug 18, 2026, with a federal patch deadline of Aug 21, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

CVE-2026-65400 is an improper authentication weakness in Apple macOS that can let an attacker on the network authenticate to Screen Sharing without valid credentials. For IT and security teams, that matters because Screen Sharing is a remote-access path: successful abuse can give an unauthenticated network attacker interactive access to a Mac that has the service reachable, with impact depending on how Screen Sharing is configured and what the session can reach.

Public detail in the record is limited to the product class (macOS), the weakness type, and the Screen Sharing authentication bypass described by CISA. Confirm exact builds, fixed releases, and configuration prerequisites against Apple’s vendor advisory before you treat any host as patched or out of scope.

How it works

This issue is classified as CWE-287 (Improper Authentication). In plain terms, the authentication checks that should prove a client is allowed to use Screen Sharing do not work as intended, so a network attacker may be able to complete authentication without legitimate credentials.

Abuse, at a high level, requires network reachability to the Screen Sharing service on a vulnerable macOS system. The attacker does not need valid Screen Sharing credentials if the flaw can be triggered as described. The record does not provide exploit mechanics, payloads, or protocol-level detail; do not assume remote code execution, privilege escalation beyond what Screen Sharing already grants, or wormable behavior unless the vendor advisory states them. Treat the realistic outcome as unauthorized remote desktop-style access via Screen Sharing when the service is exposed to the attacker’s network path.

Am I affected? How to find it in your systems

Apple macOS is the affected product. Screen Sharing (and related remote-management setups that rely on it) commonly appears on developer workstations, admin Macs, lab machines, and any host where remote GUI access was enabled for support. It may be on by default in some managed images or turned on via System Settings / remote management profiles.

How to remediate

Patch first. Apply the macOS security updates Apple designates for this vulnerability, following vendor instructions and your normal macOS update ring (test, pilot, broad deploy). CISA’s required action is to apply mitigations in accordance with vendor instructions, align with BOD 26-04 prioritization of security updates based on risk, and follow CISA’s forensics triage requirements as applicable. For cloud-adjacent or managed service contexts, follow applicable BOD 26-04 guidance; if mitigations are unavailable, discontinue use of the affected product capability as directed in that framework.

If you can't patch immediately

Reduce reachability and watch closely until the vendor update is installed.

Known ransomware use is not documented for this CVE in the provided record; still treat unauthorized Screen Sharing access as a serious incident path.

If your data may have been exposed

Actively exploited remote-access flaws often precede broader compromise, data access, or persistence. If Screen Sharing may have been reachable on vulnerable macOS hosts, investigate session history, endpoint forensics, and credential use; rotate credentials that could have been used or observed in remote sessions; and follow your incident response and CISA triage guidance. You can also run a free exposure scan of your email addresses against known breach datasets to see whether those identities already appear in public breach collections, which helps prioritize further monitoring and password resets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · macOS
WeaknessCWE-287
Added to CISA KEVAug 18, 2026
Federal patch deadlineAug 21, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities