peter bassill · operator
$ cve CVE-2026-65400 JSON

CVE-2026-65400 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 1.2% (pctl 67)

Patch first

On CISA KEV — known exploited in the wild, due 2026-08-21.

Description

An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.22% — more likely to be exploited than 67% of all CVEs
WeaknessCWE-287
On CISA KEVyes — remediate by 2026-08-21
Public exploitnone known
Published2026-08-06
Last modified2026-09-15

CISA KEV

NameApple macOS Improper Authentication Vulnerability
Added2026-08-18
Due2026-08-21
Vendor / productApple / macOS
Ransomware usenone reported

Affected (1)

VendorProduct
applemacos

References

→ the Explorer  ·  watch your stack  ·  NVD