CVE-2026-65400 is a critical improper authentication vulnerability (CWE-287) in the macOS Screen Sharing (VNC/ARD) service that allows a remote, unauthenticated network attacker to authenticate without valid credentials. Because the service runs with root-level privileges and requires no user interaction, exploitation grants direct server access. It is actively exploited in the wild and listed in CISA KEV, making it a HIGH_RISK internet-facing threat where the Screen Sharing port (TCP/5900) is exposed.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-08-06
Added to CISA KEV: 2026-08-18 12 DAYS BETWEEN CVE AND KEV
CVE-2026-65400 is a critical improper authentication vulnerability affecting the Screen Sharing component in Apple macOS [5][6]. The flaw allows a remote, unauthenticated attacker on the network to bypass credential validation requirements and gain access to the Screen Sharing service [2]. Because this service runs with root-level privileges, the vulnerability is highly dangerous, as it essentially removes the authentication barrier and grants unauthorized users access to sensitive system functions [1].
CISA added CVE-2026-65400 to the Known Exploited Vulnerabilities Catalog on August 18, 2026, and set a federal remediation due date of August 21, 2026, under BOD 26-04. NCSC-NL has reported incidents in which internet-exposed Macs with TCP/5900 open were compromised and a Monero (XMRig) miner was de…
The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to authenticate to the built-in remote desktop feature service without valid credentials. The updates released…
The vulnerability is listed in the CISA KEV catalog, but it presents a clear threat to affected systems until patched. Attackers require only that the remote desktop service be reachable; no privileged escalation beyond the service is required. Generated by OpenCVE AI on August 24, 2026 at 22:17 UTC…
Published: 06/08/2026 Updated: 07/08/2026. Vulnerability Summary. An attacker on the network may authenticate to Screen Sharing without valid credentials.CVE-2026-65400 — macOS Screen Sharing pre-auth root file read (read-only PoC) Read-only proof of concept It demonstrates the authentication bypass…
An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. Metrics. CVSS Version 4.0. CVSS Version 3.x ... This CVE is in CISA's Known Exploited Vulnerabilities Catalog Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidanc…