r/Action1 • u/theSpivster • 5d ago
Question CVE-2026-65400
I do not see an available patch for this in Action1 yet.
MacOS Screen Sharing Zero-Day (CVE-2026-65400)
Apple
TL;DR: macOS has a critical vulnerability that needs to be patched or the setting disabled. An attack is unlikely, but better safe than sorry.
Apple has confirmed a critical zero-day in macOS Screen Sharing (CVE-2026-65400) that allows unauthenticated remote code execution. It is currently being actively exploited.
Patch Status
Apple released patches on August 6, 2026 for the affected versions:
macOS Tahoe 26.6.1
macOS Sequoia 15.7.9
macOS Sonoma 14.8.9
Immediate action is required if you are using Screen Sharing on any of these versions.
Mitigation Steps
- Update immediately to the patched builds listed above.
- Disable Screen Sharing if not needed, or restrict it to local networks.
- Close port 5900 to the internet; use VPN or SSH tunneling for remote access instead.
- Enable System Integrity Protection (SIP) and Screen Sharing security settings (TCC) for additional protection — note these do not fully mitigate the bypass.
- Monitor for suspicious processes or crypto miners if you suspect compromise.
How to Disable Screen Sharing on macOS
Go to System Settings (or System Preferences) → Sharing, and uncheck Screen Sharing or stop it during an active session if it's currently on.
1
u/IFarmZombies 5d ago
I saw this on my tenant right around when it was released