## Overview
CISA added CVE-2026-65400 to its Known Exploited Vulnerabilities (KEV) list on August 18, 2026. This addition signals a federal deadline for agencies to address the vulnerability. The issue affects macOS, enabling attackers on the same network to authenticate to Screen Sharing without valid credentials.
## Technical Details
The vulnerability stems from improper authentication management within macOS. Specifically, it relates to state management during the authentication process. Apple has released updates to mitigate this issue, which are included in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, and macOS Tahoe 26.6.1. Without these updates, systems remain at risk.
## Impact
An attacker exploiting this vulnerability could gain unauthorized access to Screen Sharing features. This could lead to potential data breaches or unauthorized control over the affected macOS device. The CVSS score of 9.8 indicates a critical risk, making it essential for users to act quickly.
## Mitigation
Defenders should immediately update their macOS systems to the latest versions: Sequoia 15.7.9, Sonoma 14.8.9, or Tahoe 26.6.1. Regularly applying security updates is crucial in maintaining system integrity and protecting against potential exploitation.
CSURFACE Threat Sensor