CRITICAL
CVE-2026-65400
CVSS
9.8
KEV
Description
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Weakness (CWE)
CWE-287
Improper Authentication
EPSS Score
10.46%
Probability of exploitation in next 30 days
95.5th percentile
References
https://support.apple.com/en-us/148170
Release Notes, Vendor Advisory
https://support.apple.com/en-us/148171
Release Notes, Vendor Advisory
https://support.apple.com/en-us/148172
Release Notes, Vendor Advisory
https://support.apple.com/en-us/149035
Release Notes, Vendor Advisory
https://support.apple.com/en-us/149042
Release Notes, Vendor Advisory
http://seclists.org/fulldisclosure/2026/Aug/36
Mailing List
http://seclists.org/fulldisclosure/2026/Aug/37
Broken Link
https://advisories.ncsc.nl/2026/ncsc-2026-0280.html
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65400
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.