Authenticating to macOS Screen Sharing without valid credentials (CVE-2026-65400) — a three-day deadline, one of only 86 in 1,685 records
Apple macOS contains an improper authentication flaw that could let an attacker on the network authenticate to Screen Sharing without valid credentials. CISA added it to the KEV catalog on 2026-08-18 with a due date of 2026-08-21 — three days.
Key facts
- CVE IDCVE-2026-65400
- Affected (vendor / product)Apple macOS
- CWECWE-287
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-08-21 (U.S. federal civilian agencies, BOD 22-01)
Key points
- The affected product is Apple macOS; the name is "Apple macOS Improper Authentication Vulnerability," CWE-287.
- An attacker on the network could authenticate to Screen Sharing without valid credentials.
- Added to KEV 2026-08-18 with a due date of 2026-08-21 — three days. Of the 1,685 records this site holds as of 2026-08-28, only 86 (5.1 percent) carry a three-day deadline.
- The required action includes compliance with BOD 26-04 and with the CISA Forensics Triage Requirements.
- It also calls for discontinuing use if mitigations are unavailable; 702 of 1,685 records (41.7 percent) carry that wording.
- Three-day deadlines cover only 5.1 percent, and 70 records require forensic triage — more than fixing is asked.
1Where screen sharing sits
Screen sharing exists so that a machine can be viewed and operated from somewhere else. In practice it is used constantly for maintenance and support, and once a session is established the position is close to sitting in front of the machine. That is why it is guarded by authentication. What this record describes is a party without valid credentials passing that authentication. This is not a story about a route in; it is a story about the lock not working.
2What a three-day deadline signifies
Counting the days between listing and due date across the 1,685 KEV records this site holds as of 2026-08-28, 21 days accounts for 1,025 of them — 61 percent — followed by 14 days at 267 and 181 days at 238. Three days appears just 86 times, 5.1 percent. This record falls in that 5.1 percent. Deadlines are set according to risk under BOD 26-04, so brevity translates directly into how heavily an entry is treated.
The required action also includes compliance with the Forensics Triage Requirements, meaning the demand is not only to fix but to determine whether compromise occurred.
3Discontinuing use as an option
The required action closes with a line about discontinuing use of the product if mitigations are unavailable. Of the 1,685 records this site holds as of 2026-08-28, 702 — 41.7 percent — contain that discontinue-use wording. An instruction to stop using something when it cannot be fixed accompanies four records in ten.
Behind that phrasing sits the reality of equipment that cannot be updated and products whose updates have ended. What exploitation was actually observed is not part of this catalog record.
Why it matters
Authentication flaws slip past perimeter defenses and monitoring easily, because the authentication appears to succeed through the correct procedure. An entry with a three-day deadline that also demands investigation of compromise is not the kind that ends when the patch lands. Taking inventory of which networks can reach remote-operation features is where the response starts.
FAQ
What can be done once screen sharing is breached?
Why is the deadline three days?
What are the Forensics Triage Requirements?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- Vendor / reference advisory
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).