ZeroHour
Qualys ThreatPROTECTpublished ()ingested Diksha Ojha

CISA Warns of Apple macOS Vulnerability Exploited in Attack (CVE-2026-65400)

highExploit / PoC exploited in the wildimportance 72CVE-2026-65400
AI summary · glm-5.3-flash

CISA added actively exploited macOS flaw CVE-2026-65400 to its KEV catalog, affecting Tahoe, Sequoia, and Sonoma, with a patch deadline of August 21, 2026.

CISA acknowledged active exploitation of CVE-2026-65400, an authentication flaw affecting macOS Tahoe, Sequoia, and Sonoma, and added it to the Known Exploited Vulnerabilities Catalog. The vulnerability was discovered and reported to Apple by Alfredo Pesoli via Bynario Atlas. The remediation deadline is August 21, 2026.

  • CISA added CVE-2026-65400 to the KEV catalog
  • Authentication flaw is actively exploited in attacks
  • Affects macOS Tahoe, Sequoia, and Sonoma
  • Reported to Apple by Alfredo Pesoli via Bynario Atlas
  • Patching deadline set for August 21, 2026
VendorsAppleCISA
ProductsmacOS
CountriesUnited States

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-65400
Authentication Bypass in Apple macOS Screen Sharing

CVE-2026-65400 is a critical (CVSS 9.8) improper authentication flaw (CWE-287) in Apple macOS's Screen Sharing service, caused by an authentication state-management defect. An attacker who can reach a vulnerable Mac's Screen Sharing service over the network can authenticate without valid credentials, gaining full remote access with high impact to confidentiality, integrity, and availability. All three currently supported macOS branches are affected: Sequoia, Sonoma, and Tahoe, in versions prior to the fixed releases. The flaw is being actively exploited on the internet, with public reporting that attackers use the bypass to deploy Monero cryptominers, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-18. EPSS estimates a 9.9% probability of exploitation within 30 days (95th percentile).

Do: Upgrade to macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, or macOS Tahoe 26.6.1 (or later) immediately; patching is mandatory for federal agencies under CISA BOD 26-04 given the KEV listing. As an interim mitigation, disable Screen Sharing or restrict it via firewall/VPN so VNC (port 5900) is not reachable from the internet. Review internet-exposed Macs for signs of compromise, especially unexplained Monero miner processes or abnormal CPU usage.

9.810% KEV
  • Apple macOS (Screen Sharing service) supported macOS releases prior to the fixed builds listed below
  • Apple macOS Sequoia all versions prior to 15.7.9
  • Apple macOS Sonoma all versions prior to 14.8.9
  • +1 more
masson the order of 100M+ Macs run affected macOS versions; the directly exploitable subset is Macs with Screen Sharing enabled and internet-reachable
Full article

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently acknowledged the active exploitation of the macOS vulnerability. Tracked as CVE-2026-65400, the vulnerability affects macOS Tahoe, macOS Sequoia, and macOS Sonoma. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before August 21, 2026. Alfredo Pesoli via Bynario Atlas discovered and reported the vulnerability to Apple. The authentication flaw impacts the … Continue reading "CISA Warns of Apple macOS Vulnerability Exploited in Attack (CVE-2026-65400)"

This source does not provide full text. Read it at threatprotect.qualys.com.