Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Apple macOS Screen Sharing Security Flaw

A serious security flaw in Apple macOS allows attackers on the same network to access Screen Sharing without needing a password. This vulnerability is actively being exploited and affects several recent macOS versions, making it important for organisations using Apple computers to act quickly.

19 August 2026

Reference: CVE-2026-65400

1. What is being reported?

Researchers have found a problem in macOS where the system does not properly check who is trying to connect via Screen Sharing. This means someone on the same network could connect to your Mac remotely without logging in properly.

2. What this means in plain English

If an attacker gains access to your network, they could view or control your Mac through Screen Sharing without permission. This could lead to data theft, disruption, or unauthorised changes to your systems.

3. Could this affect a small business?

Any small business, charity, or club using Apple Macs with Screen Sharing enabled on the affected macOS versions could be at risk, especially if devices are on shared or public networks. Organisations not using Macs or not enabling Screen Sharing are unlikely to be affected.

4. What to do now

  • Check if your Macs are running macOS Sequoia 15.7.9, Sonoma 14.8.9, or Tahoe 26.6.1 or later and update if not.
  • Disable Screen Sharing on Macs if it is not needed.
  • Ensure your network is secure, especially Wi-Fi networks, to prevent unauthorised access.
  • Ask your IT provider to apply all recommended security updates promptly following official guidance.

5. Ask your IT provider

Can you confirm if our Macs are protected against the recent Screen Sharing vulnerability CVE-2026-65400 and that all necessary updates or mitigations have been applied?

6. Bottom line

Keep your Macs updated and disable Screen Sharing if you don’t need it to prevent unauthorised remote access.

Information based on CISA KEV, NVD, and reputable security reporting.

Back to Vulnerability Briefs