🔴 CVE-2026-65400

CVE-2026-65400 is a critical improper authentication vulnerability (CWE-287) in the macOS Screen Sharing (VNC/ARD) service that allows a remote, unauthenticated network attacker to authenticate without valid credentials. Because the service runs with root-level privileges and requires no user interaction, exploitation grants direct server access. It is actively exploited in the wild and listed in CISA KEV, making it a HIGH_RISK internet-facing threat where the Screen Sharing port (TCP/5900) is exposed.

← Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
MEDIUM
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-08-06

Added to CISA KEV: 2026-08-18 12 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-09-14)

Summary

CVE-2026-65400 is a critical improper authentication vulnerability affecting the Screen Sharing component in Apple macOS [5][6]. The flaw allows a remote, unauthenticated attacker on the network to bypass credential validation requirements and gain access to the Screen Sharing service [2]. Because this service runs with root-level privileges, the vulnerability is highly dangerous, as it essentially removes the authentication barrier and grants unauthorized users access to sensitive system functions [1].

Exploitation

  • Active Exploitation: The vulnerability is under active exploitation in the wild and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog [1][5].
  • Campaigns: Threat actors have been observed targeting internet-exposed macOS systems to deploy cryptocurrency miners (specifically XMRig) [1].
  • PoC Availability: Read-only proof-of-concept code has been documented, which demonstrates the ability to read root-owned files without triggering common indicators of compromise like RCE chains [4].
  • Prerequisites: Exploitation can occur from any network position that can reach the target machine’s Screen Sharing port (typically TCP/5900) [3]. No authentication, special privileges, or user interaction are required [2][3].

Affected Products & Patches

  • Affected Versions: The vulnerability impacts macOS releases prior to the security updates issued by Apple in August 2026 [3].
  • Patch Availability: Apple released security updates that improve state management mechanisms to enforce correct credential validation; users should update to these patched versions immediately [2].
  • Mitigations: Until patched, systems should not expose the Screen Sharing port (TCP/5900) to the internet; organizations should treat any unpatched, reachable macOS system as potentially compromised and perform a host-forensics review [1].

Impact

  • Access/Capability: Successful exploitation grants an attacker unauthorized access to the Screen Sharing service, allowing them to interact with the system at a root-privileged level [1]. This can lead to unauthorized file reads and potential further system compromise.
  • Business Risk: For internet-facing deployments, the risk is severe (CVSS 9.8), as the service is directly reachable by automated scanners and botnets looking to exploit known vulnerabilities [2][3]. Compromise of such systems can lead to unauthorized access to corporate data, resource hijacking (e.g., crypto-mining), and persistent backdoors [1].

Sources

  1. Resecurity | CVE-2026-65400: macOS Screen Sharing Authentication...

    CISA added CVE-2026-65400 to the Known Exploited Vulnerabilities Catalog on August 18, 2026, and set a federal remediation due date of August 21, 2026, under BOD 26-04. NCSC-NL has reported incidents in which internet-exposed Macs with TCP/5900 open were compromised and a Monero (XMRig) miner was de…

  2. Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed...

    The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to authenticate to the built-in remote desktop feature service without valid credentials. The updates released…

  3. CVE-2026-65400 - Vulnerability Details - OpenCVE

    The vulnerability is listed in the CISA KEV catalog, but it presents a clear threat to affected systems until patched. Attackers require only that the remote desktop service be reachable; no privileged escalation beyond the service is required. Generated by OpenCVE AI on August 24, 2026 at 22:17 UTC…

  4. CVE-2026-65400 - Network Authentication Bypass in macOS

    Published: 06/08/2026 Updated: 07/08/2026. Vulnerability Summary. An attacker on the network may authenticate to Screen Sharing without valid credentials.CVE-2026-65400 — macOS Screen Sharing pre-auth root file read (read-only PoC) Read-only proof of concept It demonstrates the authentication bypass…

  5. NVD-CVE-2026-65400 - National Vulnerability Database

    An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. Metrics. CVSS Version 4.0. CVSS Version 3.x ... This CVE is in CISA's Known Exploited Vulnerabilities Catalog Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidanc…