EXPOSURES › CVE-2026-65400
CVE-2026-65400
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unpatched macOS Screen Sharing vulnerability allowed network attackers to authenticate without valid credentials, enabling unauthorized access to systems.
This improper authentication flaw in macOS Screen Sharing lets attackers bypass credential checks, granting them direct access to a system's screen and controls. For DIB organizations, this means unpatched endpoints are vulnerable to lateral movement and data exfiltration, violating NIST 800-171 requirements for patch management and access control. Organizations must enforce strict patching cycles and disable unused services like Screen Sharing on untrusted networks.
Shame score — A known authentication bypass in a widely deployed consumer OS that remains in KEV indicates negligent patching and avoidable exposure to network attackers.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.