CVE-2026-65400: Apple macOS Improper Authentication Vulnerability
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Other sources
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
— CISA
Screen Sharing. An authentication issue was addressed with improved state management.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.7.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.6.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.8.9 - Upgrade
Upgrade
Apple macOS Screen Sharingto a version that resolves this vulnerability.Fixed in 15.7.9 - Upgrade
Upgrade
Apple macOS Screen Sharingto a version that resolves this vulnerability.Fixed in 14.8.9 - Upgrade
Upgrade
Apple macOS Screen Sharingto a version that resolves this vulnerability.Fixed in 26.6.1 - Compensating control
Follow CISA’s BOD 26-04 guidance: evaluate each asset’s internet exposure and ensure adherence to BOD 26-04 patching guidelines for mitigations or discontinue use of Screen Sharing if mitigations are unavailable.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2026-65400?
CVE-2026-65400 has a risk rating of 37, indicating a significant security impact.
What type of vulnerability is CVE-2026-65400?
CVE-2026-65400 addresses an authentication issue related to screen sharing.
How do I fix CVE-2026-65400?
To fix CVE-2026-65400, ensure you update your Apple macOS to the latest version available.
Which Apple macOS versions are affected by CVE-2026-65400?
CVE-2026-65400 affects Apple macOS Sequoia, Tahoe, and Sonoma versions.
What does CVE-2026-65400 improve in terms of security?
CVE-2026-65400 improves state management to enhance authentication security during screen sharing.