CVE-2026-65400
published 2026-08-06CVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An…
PriorityP182critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-08-21
Exploited in the wild
EPSS
9.90%
95.2th percentile
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 14.8.9 | 14.8.9 |
| apple | macos | < 15.7.9 | 15.7.9 |
| apple | macos | < 26.6.1 | 26.6.1 |
| apple | macos | >= 14.0 < 14.8.9 | 14.8.9 |
| apple | macos | >= 15.0 < 15.7.9 | 15.7.9 |
| apple | macos | >= 26.0 < 26.6.1 | 26.6.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck7.1HIGH
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple macOS Improper Authentication Vulnerability
cisa·2026-08-18·CVSS 9.8
CVE-2026-65400 [CRITICAL] CWE-287 Apple macOS Improper Authentication Vulnerability
Vulnerability: Apple macOS Improper Authentication Vulnerability
Affected: Apple macOS
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Notes: https://support.apple.com/en-u
GHSA
An authentication issue was addressed with improved state management.
ghsa_unreviewed·2026-08-07
CVE-2026-65400 An authentication issue was addressed with improved state management.
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
VulDB
Apple macOS up to 14.8.8/15.7.8/26.6.0 Screen Sharing improper authentication
vuldb·2026-08-07
CVE-2026-65400 [CRITICAL] Apple macOS up to 14.8.8/15.7.8/26.6.0 Screen Sharing improper authentication
A vulnerability was found in Apple macOS up to 14.8.8/15.7.8/26.6.0. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component Screen Sharing. This manipulation causes improper authentication.
This vulnerability is handled as CVE-2026-65400. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
VulnCheck
Apple macos Improper Authentication
vulncheck·2026·CVSS 7.1
CVE-2026-65400 [HIGH] Apple macos Improper Authentication
Apple macos Improper Authentication
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Affected: Apple macos
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://advisories.ncsc.nl/2026/ncsc-2026-0280.html
No detection rules found.
No public exploits indexed.
Hackernews
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
blogs_hackernews·2026-08-19·CVSS 9.8
CVE-2026-65400 [CRITICAL] Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities ( KEV ) catalog, stating they are being exploited in the wild.
The shortcomings added to the KEV catalog are listed below -
CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
CVE-2026-55040 (CVSS score: 9.1) - A weak authentication vulnerab
Checkpoint
17th August – Threat Intelligence Report
blogs_checkpoint·2026-08-17
CVE-2026-68820 17th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 17th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were encrypted but stated that no data theft was detected during the incident.
MyDr, Poland’s primary
Hackernews
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
blogs_hackernews·2026-08-17·CVSS 9.8
CVE-2026-59310 [CRITICAL] ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones.
This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely.
So, nothing magical. Just a lot of small openings turning into bigger problems. Here’s what stood out.
## ⚡ Threat of the Week
Suspected China APT Behind Exploitation of New V
Hackernews
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
blogs_hackernews·2026-08-15·CVSS 9.8
CVE-2026-65400 [CRITICAL] Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned .
The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to authenticate to the built-in remote desktop feature service without valid credentials.
The updates released by Apple improve state management mechan
Hackernews
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
blogs_hackernews·2026-08-10
CVE-2026-34348 ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.
That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place.
That’s only part of it. Here’s everything else that made the Monday recap.
## ⚡ Threat of the Week
Anthropic's Model Attempts to Poison Open-Source Project — A new evaluati
Huntress
From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOS
blogs_huntress·2026-08-07·CVSS 8.6
CVE-2026-43760 [HIGH] From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOS
Acknowledgments : Special thanks to Bryan Masters and Stuart Ashenbrenner for their contributions to this investigation and write - up.
## TL;DR :
If you're running Screen Sharing on macOS and exposing it to the public internet, then we need to talk. While it's generally frowned upon to expose remote access protocols to the world, we understand that some use cases may require it. You do you!
With the uptick in hosted bare-metal Apple devices, such as the Mac mini available for on-demand workloads, SSH and Screen Sharing are commonly enabled by default on any newly provisioned service.
Apple's security releases announced in the last week of July were followed by a flurry of activity, public disclosures of newly patched bugs, and commentary on the scale of the CVEs listed. With this come
https://support.apple.com/en-us/148170https://support.apple.com/en-us/148171https://support.apple.com/en-us/148172http://seclists.org/fulldisclosure/2026/Aug/36http://seclists.org/fulldisclosure/2026/Aug/37https://advisories.ncsc.nl/2026/ncsc-2026-0280.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65400
2026-08-06
Published
2026-08-18
Added to CISA KEV
Exploited in the wild