Knox CVE Database
/
CVE-2026-65400
Critical
9.8

CVE-2026-65400: Apple macOS Improper Authentication Vulnerability

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

Added to the CISA KEV catalog:
August 18, 2026

Overview

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

Vulnerability details

Affected vendor
Apple
Affected product
macOS
Weakness type (CWE)
CWE-287

CVE-2026-65400 is an improper authentication vulnerability (CWE-287) in the macOS Screen Sharing service. The flaw stems from defective authentication state management: the service's credential validation logic can be bypassed entirely, accepting an authentication attempt as successful without the attacker supplying valid credentials. Screen Sharing, built on VNC and Apple Remote Desktop protocols, grants full remote desktop access once authenticated, making any bypass of its credential check a critical exposure.


An attacker with network access to a macOS system where Screen Sharing is enabled sends crafted authentication traffic to the Screen Sharing service without valid credentials. The service's flawed state management incorrectly accepts the session as authenticated, granting the attacker full remote desktop control equivalent to interactive local access, with high confidentiality, integrity, and availability impact. Exploitation requires Screen Sharing to be enabled and the service to be reachable from the attacker's network position.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review macOS Screen Sharing logs for authenticated sessions that have no corresponding successful credential exchange, particularly sessions originating from hosts not in the configured user access list.
  • Audit system logs for Screen Sharing connections (ARD/VNC on TCP 5900) from sources outside expected administrative subnets, especially where no prior authentication failure precedes a successful session.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 21, 2026

Additional hardening

  • Upgrade macOS Sonoma to 14.8.9 or later, macOS Sequoia to 15.7.9 or later, and macOS Tahoe to 26.6.1 or later. See References for vendor advisories covering all three release lines.
  • Disable Screen Sharing on all macOS systems where remote desktop access is not operationally required. System Preferences > Sharing > Screen Sharing should be off by default on non-administrative endpoints.
  • Restrict access to TCP port 5900 at the network perimeter and host-based firewall level, limiting Screen Sharing reachability to explicitly authorized management subnets only.
  • Audit all macOS endpoints for Screen Sharing enablement state and review access control lists to ensure only named, authorized users are permitted, reducing the attack surface while patching is completed.

Key dates

Published (NVD)
August 6, 2026
Added to CISA KEV
August 18, 2026
Remediation deadline
August 21, 2026
Last updated
August 19, 2026

References

Frequently asked questions

Does CVE-2026-65400 affect my FedRAMP authorization?

If Apple macOS runs inside your authorization boundary, CVE-2026-65400 affects your FedRAMP authorization directly. CISA has listed this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of August 21, 2026. An unpatched KEV inside your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it as a deficiency.

How does Knox help me handle CVE-2026-65400?

Knox does not patch your software. Remediating Apple macOS is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you manage on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-65400 surfaces, exposure is identified through ongoing monitoring rather than waiting for an assessor to flag it at a scheduled review.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-65400 isn't remediated by August 21, 2026?

Missing the August 21, 2026 deadline turns CVE-2026-65400 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization clean and preserves the agency relationship.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting