CISA adds the macOS Screen Sharing bypass CVE-2026-65400 to its KEV catalog (August 18, 2026)

Chapters
TL;DR
CVE-2026-65400, the Screen Sharing authentication bypass in macOS Tahoe 26.6 and earlier, was added to the Known Exploited Vulnerabilities catalog by CISA on August 18, 2026. Nothing about the bug changed on this day: what changed is that patching it became an obligation for US federal civilian agencies under Binding Operational Directive 26-04. The fix has been available since August 6, 2026, the date Apple Support put on the macOS Tahoe 26.6.1 security note, with macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9 as the sibling updates.
- New on August 18, 2026: the KEV listing, which turns a recommended update into a directed one for federal agencies.
- CISA added four CVEs that day, one of them Apple's improper authentication flaw in macOS.
- BOD 26-04 covers publicly exposed assets where exploitation grants total control of the asset.
- CISA's alert page itself prints no remediation due date for the four additions.
- Also on August 18, 2026: Safari 26.6.1 backported the WebKit fixes to macOS Sonoma and macOS Sequoia.
What the KEV listing changes
CISA added four vulnerabilities to the catalog on August 18, 2026: CVE-2026-33824 in Microsoft IKE Service Extensions, a double free; CVE-2026-55040 in Microsoft SharePoint, weak authentication; CVE-2026-59310 in Broadcom VMware vCenter, path traversal; and CVE-2026-65400, described as Apple macOS improper authentication.
The applicable directive is BOD 26-04, which CISA says "requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA's KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation". An internet-facing Mac that hands out root through port 5900 is exactly that description.
One honest limit: the alert page names no remediation due date for these four entries, so I am not going to quote one. If you run federal systems, the catalog entry rather than the alert is where a date would live.
| CVE | Product | Weakness |
|---|---|---|
| CVE-2026-33824 | Microsoft IKE Service Extensions | Double free |
| CVE-2026-55040 | Microsoft SharePoint | Weak authentication |
| CVE-2026-59310 | Broadcom VMware vCenter | Path traversal |
| CVE-2026-65400 | Apple macOS | Improper authentication |
The bug itself has not changed
The behaviour is the same one I wrote up in the August 14 post. A network attacker reaches Screen Sharing on TCP port 5900 and is treated as authenticated without valid credentials. BleepingComputer reported on August 14, 2026 that the Dutch national cyber security centre had observed "active abuse of this vulnerability" on multiple systems with port 5900 reachable from the internet, and that in confirmed cases attackers "obtained root access to the system and deployed a Monero cryptocurrency miner".
Fixed versions are macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9, all from August 6, 2026. Nothing further shipped for this CVE on August 18, 2026.
Safari 26.6.1 landed the same day
The other Apple release on August 18, 2026 was Safari 26.6.1, and its security note from Apple Support lists it as "Available for: macOS Sonoma and macOS Sequoia". It backports to those older lines the WebKit fixes that macOS Tahoe received a day earlier in 26.6.2, including CVE-2026-64784, CVE-2026-43795, CVE-2026-65338, CVE-2026-65341 and CVE-2026-64782.
Most of those entries read "Processing maliciously crafted web content may lead to an unexpected Safari crash", while CVE-2026-65341 and CVE-2026-43794 read "may lead to memory corruption". Two more are worth naming: WebKit History CVE-2026-64778, where "Visiting a maliciously crafted website may leak sensitive data", and WebKit Storage CVE-2026-64779, a memory corruption vulnerability addressed with improved locking. Nine of the WebKit entries are credited to OpenAI Codex Security, Amy Burnett.
What a KEV listing does not do
It does not clean anything. If your Mac was reachable on port 5900 before August 6, 2026, updating it removes the entry route and leaves whatever was installed through that route in place: added launch daemons, added accounts, a miner. That machine needs to be examined by a person, and the listing does not change that arithmetic.
It also does not make the stopgap cheaper. Switching Screen Sharing and Remote Management off in System Settings, General, Sharing costs you remote screen access entirely, which for an unattended Mac can mean a trip to the machine.
What to do today
1. Install macOS Tahoe 26.6.1 or later, or macOS Sequoia 15.7.9 or macOS Sonoma 14.8.9, from System Settings, General, Software Update. On macOS Tahoe the newer 26.6.2, which I covered in the August 17 post, carries this fix as well.
2. On macOS Sonoma and macOS Sequoia, also install Safari 26.6.1 while you are in Software Update.
3. Until the Mac is patched, switch Screen Sharing and Remote Management off in System Settings, General, Sharing, and stop forwarding TCP port 5900 from the internet.
4. For any Mac that was exposed on port 5900, audit it: unfamiliar items in /Library/LaunchDaemons, accounts you did not create, a process holding the processor at full load.
5. If you manage Macs for other people, check the fleet by version rather than by memory. A Mac last updated before August 6, 2026 does not have this fix, however recently it feels like it was touched.
If you would rather have that checked and patched for you, Get XLAnt.