CVE Details

CVE-2026-65400 Apple macOS Improper Authentication Vulnerability
Published: 2026-08-18 CVSS: 9.8 CRITICAL Product: Apple macOS Due Date: 2026-08-21

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 9.8
  • Severity: CRITICAL
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC

  • Exploitation: active
  • Automatable: yes
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
dataVersion 5.2
cveMetadata > cveId CVE-2026-65400
cveMetadata > assignerOrgId 286789f9-fbc2-4510-9f9a-43facdede74c
cveMetadata > state PUBLISHED
cveMetadata > assignerShortName apple
cveMetadata > dateReserved 2026-07-22T00:46:56.740Z
cveMetadata > datePublished 2026-08-06T18:17:18.263Z
cveMetadata > dateUpdated 2026-08-18T17:47:27.161Z
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > description An attacker on the network may be able to authenticate to Screen Sharing without valid credentials
containers > cna > affected > 0 > vendor Apple
containers > cna > affected > 0 > product macOS
containers > cna > affected > 0 > versions > 0 > version 0
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > lessThan 14.8.9
containers > cna > affected > 0 > versions > 0 > versionType custom
containers > cna > affected > 0 > versions > 1 > version 0
containers > cna > affected > 0 > versions > 1 > status affected
containers > cna > affected > 0 > versions > 1 > lessThan 15.7.9
containers > cna > affected > 0 > versions > 1 > versionType custom
containers > cna > affected > 0 > versions > 2 > version 0
containers > cna > affected > 0 > versions > 2 > status affected
containers > cna > affected > 0 > versions > 2 > lessThan 26.6.1
containers > cna > affected > 0 > versions > 2 > versionType custom
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
containers > cna > references > 0 > url https://support.apple.com/en-us/148170
containers > cna > references > 1 > url https://support.apple.com/en-us/148171
containers > cna > references > 2 > url https://support.apple.com/en-us/148172
containers > cna > providerMetadata > orgId 286789f9-fbc2-4510-9f9a-43facdede74c
containers > cna > providerMetadata > shortName apple
containers > cna > providerMetadata > dateUpdated 2026-08-06T18:17:18.263Z
containers > adp > 0 > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > adp > 0 > metrics > 0 > cvssV3_1 > version 3.1
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseScore 9.8
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseSeverity CRITICAL
containers > adp > 0 > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
containers > adp > 0 > metrics > 0 > cvssV3_1 > integrityImpact HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > adp > 0 > metrics > 0 > cvssV3_1 > availabilityImpact HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > adp > 0 > metrics > 1 > other > type ssvc
containers > adp > 0 > metrics > 1 > other > content > id CVE-2026-65400
containers > adp > 0 > metrics > 1 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 1 > other > content > options > 0 > Exploitation active
containers > adp > 0 > metrics > 1 > other > content > options > 1 > Automatable yes
containers > adp > 0 > metrics > 1 > other > content > options > 2 > Technical Impact total
containers > adp > 0 > metrics > 1 > other > content > version 2.0.3
containers > adp > 0 > metrics > 1 > other > content > timestamp 2026-08-18T17:44:20.737833Z
containers > adp > 0 > references > 0 > url https://advisories.ncsc.nl/2026/ncsc-2026-0280.html
containers > adp > 0 > references > 0 > tags > 0 third-party-advisory
containers > adp > 0 > references > 1 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65400
containers > adp > 0 > references > 1 > tags > 0 government-resource
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > lang en
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > type CWE
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > cweId CWE-287
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > description CWE-287 Improper Authentication
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-08-18T17:47:27.161Z
containers > adp > 1 > title CVE Program Container
containers > adp > 1 > references > 0 > url http://seclists.org/fulldisclosure/2026/Aug/36
containers > adp > 1 > references > 1 > url http://seclists.org/fulldisclosure/2026/Aug/37
containers > adp > 1 > providerMetadata > orgId af854a3a-2127-422b-91ae-364da2661108
containers > adp > 1 > providerMetadata > shortName CVE
containers > adp > 1 > providerMetadata > dateUpdated 2026-08-13T23:15:32.774Z