Skip to content
COOEY

EXPOSURES › CVE-2026-65400

CVE-2026-65400

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-08-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-65400 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatched

An unpatched macOS Screen Sharing vulnerability allowed network attackers to authenticate without valid credentials, enabling unauthorized access to systems.

This improper authentication flaw in macOS Screen Sharing lets attackers bypass credential checks, granting them direct access to a system's screen and controls. For DIB organizations, this means unpatched endpoints are vulnerable to lateral movement and data exfiltration, violating NIST 800-171 requirements for patch management and access control. Organizations must enforce strict patching cycles and disable unused services like Screen Sharing on untrusted networks.

Shame score — A known authentication bypass in a widely deployed consumer OS that remains in KEV indicates negligent patching and avoidable exposure to network attackers.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.