← All Advisories

CVE-2026-65400: Apple macOS Improper

Status: KEV  |  Advisory ID: CVE-2026-65400

Key Details

CVECVE-2026-65400
CVSSCVSS 9.8 (Critical).
Affected productsApple macOS
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
Classified asCWE-287 (Improper Authentication)
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-08-18.
Exploitation prediction (EPSS)10% probability of exploitation in the next 30 days (96% percentile) -- FIRST.org's EPSS model.
Federal remediation deadline2026-08-21 (CISA KEV, Binding Operational Directive).

What to Know

An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-65400