Apply the latest macOS security updates released by Apple to address CVE-2026-65400. Restrict Screen Sharing access to trusted networks and disable Screen Sharing if not required. Monitor system resources for unexpected cryptocurrency mining activity.
Quick answers
What is CVE-2026-65400?
Apply the latest macOS security updates released by Apple to address CVE-2026-65400. Restrict Screen Sharing access to trusted networks and disable Screen Sharing if not required. Monitor system resources for unexpected cryptocurrency mining activity.
How severe is CVE-2026-65400?
critical, CVSS 9.8
Is CVE-2026-65400 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-65400 be mitigated?
Apply the latest macOS security updates released by Apple to address CVE-2026-65400. Restrict Screen Sharing access to trusted networks and disable Screen Sharing if not required. Monitor system resources for unexpected cryptocurrency mining activity.
CVSS
9.8
Vendor
Apple
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
macOS
Mitigation
Apply the latest macOS security updates released by Apple to address CVE-2026-65400. Restrict Screen Sharing access to trusted networks and disable Screen Sharing if not required. Monitor system resources for unexpected cryptocurrency mining activity.
On August 18, 2026, CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild. The additions include a Microsoft IKE Service Extensions double-free flaw, a SharePoint authentication bypass, a VMware vCenter path traversal, and an macOS improper authentication issue. CISA's Binding Operational Directive 26-04 reinforces rapid remediation requirements for Federal Civilian Executive Branch agencies on publicly exposed assets.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation in the wild. The newly listed flaws span Apple macOS, Microsoft SharePoint, VMware vCenter Server, and Microsoft IKE. CISA's action triggers mandatory patching timelines for federal agencies and strongly encourages immediate remediation for all organizations.
The Netherlands National Cyber Security Centre (NCSC-NL) has issued an advisory warning that a critical authentication flaw in Apple macOS Screen Sharing (CVE-2026-65400, CVSS 9.8) is being actively exploited in the wild. Attackers are leveraging the vulnerability to gain unauthorized access to internet-exposed macOS systems and deploy a Monero cryptocurrency miner. Apple has released security updates to address the vulnerability, and users are strongly advised to apply the latest macOS updates immediately.