ZeroDayAlert

CVE-2026-65400: Apple macOS Improper Authentication Vulnerability

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

Apple macOS Added to KEV 2026-08-18 Federal due 2026-08-21 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

This vulnerability affects Apple macOS systems where Screen Sharing is enabled or accessible. An attacker positioned on the same network can authenticate to Screen Sharing without valid credentials, gaining remote access to the affected system. The record does not specify which macOS versions are vulnerable, which specific Screen Sharing deployment configurations are at risk, or whether internet-facing Screen Sharing is required for exploitation.

How to check whether this touches you

  • Inventory which of your macOS systems have Screen Sharing enabled (System Settings > General > Sharing > Screen Sharing).
  • Confirm whether Screen Sharing is reachable from your network perimeter or whether it is restricted to internal subnets only.
  • Check the macOS version on each affected system; version-specific guidance will be available from Apple once a patch is released.
  • If Screen Sharing is not in active use, document whether it is disabled at the firmware or policy level or merely inactive.

What to do

  1. If Screen Sharing is not operationally required, disable it immediately via System Settings > General > Sharing.
  2. If Screen Sharing must remain enabled, restrict access to it at the network level (firewall rules, VPN gateways) to trusted internal subnets only; do not expose it to untrusted networks.
  3. Monitor your CISA advisories and Apple security updates for patch availability; Apple's guidance under BOD 26-04 will indicate the deadline for your asset's risk category.
  4. Enable logging on Screen Sharing sessions (if available) and centralise those logs for review.
  5. Once a patch is released, prioritise patching according to your asset's exposure rating and BOD 26-04 timelines.
  6. If no patch becomes available or if your macOS version reaches end of support, escalate to your risk and architecture teams; discontinuation of the product may be required.

If you find you were exposed

Screen Sharing access logs will be your primary forensic signal; review them for any authentication attempts or sessions from unfamiliar source addresses. Because exploitation typically predates public disclosure by weeks or months, retrospective hunts should cover at least the last three months of available logs. If logs have been purged or are incomplete, consult your incident response team to establish a baseline of compromised assets. Any authenticated Screen Sharing sessions from external or untrusted network sources should be treated as suspected breach activity.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-65400 is being exploited. It cannot tell you whether macOS is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →