Exploited Known exploited (KEV) CVE-2026-65400

Authenticating to macOS Screen Sharing without valid credentials (CVE-2026-65400) — a three-day deadline, one of only 86 in 1,685 records

Apple macOS Added to KEV Aug 18, 2026 Federal remediation due 2026-08-21

Apple macOS contains an improper authentication flaw that could let an attacker on the network authenticate to Screen Sharing without valid credentials. CISA added it to the KEV catalog on 2026-08-18 with a due date of 2026-08-21 — three days.

Key facts

  • CVE IDCVE-2026-65400
  • Affected (vendor / product)Apple macOS
  • CWECWE-287
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-08-21 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • The affected product is Apple macOS; the name is "Apple macOS Improper Authentication Vulnerability," CWE-287.
  • An attacker on the network could authenticate to Screen Sharing without valid credentials.
  • Added to KEV 2026-08-18 with a due date of 2026-08-21 — three days. Of the 1,685 records this site holds as of 2026-08-28, only 86 (5.1 percent) carry a three-day deadline.
  • The required action includes compliance with BOD 26-04 and with the CISA Forensics Triage Requirements.
  • It also calls for discontinuing use if mitigations are unavailable; 702 of 1,685 records (41.7 percent) carry that wording.
  • Three-day deadlines cover only 5.1 percent, and 70 records require forensic triage — more than fixing is asked.

1Where screen sharing sits

Screen sharing exists so that a machine can be viewed and operated from somewhere else. In practice it is used constantly for maintenance and support, and once a session is established the position is close to sitting in front of the machine. That is why it is guarded by authentication. What this record describes is a party without valid credentials passing that authentication. This is not a story about a route in; it is a story about the lock not working.

2What a three-day deadline signifies

Counting the days between listing and due date across the 1,685 KEV records this site holds as of 2026-08-28, 21 days accounts for 1,025 of them — 61 percent — followed by 14 days at 267 and 181 days at 238. Three days appears just 86 times, 5.1 percent. This record falls in that 5.1 percent. Deadlines are set according to risk under BOD 26-04, so brevity translates directly into how heavily an entry is treated.

The required action also includes compliance with the Forensics Triage Requirements, meaning the demand is not only to fix but to determine whether compromise occurred.

Records with a three-day deadline865.1 percent of the 1,685 held as of 2026-08-28
Records requiring forensic triage70of the 1,687 held as of 2026-09-01
This record3 days plus a compromise assessmentfixing alone is not what is asked

3Discontinuing use as an option

The required action closes with a line about discontinuing use of the product if mitigations are unavailable. Of the 1,685 records this site holds as of 2026-08-28, 70241.7 percent — contain that discontinue-use wording. An instruction to stop using something when it cannot be fixed accompanies four records in ten.

Behind that phrasing sits the reality of equipment that cannot be updated and products whose updates have ended. What exploitation was actually observed is not part of this catalog record.

Why it matters

Authentication flaws slip past perimeter defenses and monitoring easily, because the authentication appears to succeed through the correct procedure. An entry with a three-day deadline that also demands investigation of compromise is not the kind that ends when the patch lands. Taking inventory of which networks can reach remote-operation features is where the response starts.

FAQ

What can be done once screen sharing is breached?
Screen sharing lets a machine be viewed and operated from elsewhere, so an established session is close to sitting in front of it. That is why it is guarded by authentication.
Why is the deadline three days?
Deadlines are set according to risk under BOD 26-04. Across the 1,685 records this site holds as of 2026-08-28, 21 days accounts for 61 percent while three days is 5.1 percent, so brevity reflects how heavily the entry is treated.
What are the Forensics Triage Requirements?
A CISA document named in the required action, meaning the demand extends beyond applying an update to determining whether compromise occurred. Its contents are not part of the catalog record.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Security#CISA#KEV#Apple#macOS#Authentication
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.