MACOS · AUGUST 2026 · CONFIRMED

Apple macOS Improper Authentication Vulnerability CVE-2026-65400 Confirmed

Severity
HIGH
Affected component
apple (macos)
Patched version
Not yet available
CVE-2026-65400

Apple macOS has been confirmed to contain an improper authentication vulnerability, tracked as CVE-2026-65400, which could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

What happened

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-65400 to its Known Exploited Vulnerabilities (KEV) catalog, indicating that this vulnerability is being actively exploited in the wild. The vulnerability, with a CVSS score of 9.8, allows an attacker to bypass authentication mechanisms in Apple macOS Screen Sharing. This could potentially lead to unauthorized access and further exploitation of affected systems.

According to multiple public reports, the Apple macOS flaw has been abused to deliver a Monero cryptocurrency miner. It is crucial for users to ensure their macOS systems are updated to the latest version to mitigate the risk of exploitation.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If apple is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Apple macOS, you may be affected by this vulnerability. It is recommended to check for and apply the latest updates.

What should I do right now?

Ensure your macOS systems are updated to the latest version. Monitor official sources for updates and consider implementing additional network-level protections.

Has this been exploited in the wild?

Yes, this vulnerability has been confirmed to be exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats