AppleCVE-2026-65400
Apple macOS: improper authentication
Critical9.8CVE-2026-65400 · Published Aug 6, 2026 · updated Sep 15, 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| macOS Product | < 14.8.9 | 14.8.9 |
| < 15.7.9 | 15.7.9 | |
| < 26.6.1 | 26.6.1 | |
| < 26.7 | 26.7 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-287
- www.cve.org/CVERecord?id=CVE-2026-65400
- nvd.nist.gov/vuln/detail/CVE-2026-65400
- support.apple.com/en-us/148170
- support.apple.com/en-us/148171
- support.apple.com/en-us/148172
- support.apple.com/en-us/149035
- support.apple.com/en-us/149042
- seclists.org/fulldisclosure/2026/Aug/36
- seclists.org/fulldisclosure/2026/Aug/37
- advisories.ncsc.nl/2026/ncsc-2026-0280.html
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65400
More Apple advisories
All Apple| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | ## Impact A malicious builder peer may be able to use the `json` response mode... | Low | 1.2.0 |
| Aug 12 | Build filesystem sync discloses host files outside the build context via symlinks | Medium | 1.2.0 |
| Aug 12 | TCP port forwarder buffers unbounded pre-connect data from published container ports | Medium | 1.2.0 |
| Aug 12 | HTTP Request Smuggling due to mishandled Transfer-Encoding parsing | Medium6.5 | 0.42.65 |
| Aug 11 | ## Impact The author or publisher of any container image | Medium | 0.40.0+1 more |
| Aug 11 | ## Impact An attacker who publishes a malicious image with bare-name... | Medium | 1.2.0 |