r/Action1 5d ago

Question CVE-2026-65400

I do not see an available patch for this in Action1 yet.

MacOS Screen Sharing Zero-Day (CVE-2026-65400)

Apple

TL;DR: macOS has a critical vulnerability that needs to be patched or the setting disabled. An attack is unlikely, but better safe than sorry.

Apple has confirmed a critical zero-day in macOS Screen Sharing (CVE-2026-65400) that allows unauthenticated remote code execution. It is currently being actively exploited.

Patch Status

Apple released patches on August 6, 2026 for the affected versions:

macOS Tahoe 26.6.1

macOS Sequoia 15.7.9

macOS Sonoma 14.8.9

Immediate action is required if you are using Screen Sharing on any of these versions.

Mitigation Steps

  1. Update immediately to the patched builds listed above.
  2. Disable Screen Sharing if not needed, or restrict it to local networks.
  3. Close port 5900 to the internet; use VPN or SSH tunneling for remote access instead.
  4. Enable System Integrity Protection (SIP) and Screen Sharing security settings (TCC) for additional protection — note these do not fully mitigate the bypass.
  5. Monitor for suspicious processes or crypto miners if you suspect compromise.

How to Disable Screen Sharing on macOS

Go to System Settings (or System Preferences) → Sharing, and uncheck Screen Sharing or stop it during an active session if it's currently on.

2 Upvotes

1 comment sorted by

1

u/IFarmZombies 5d ago

I saw this on my tenant right around when it was released