Apple has released macOS Tahoe 26.6.1 to patch a Screen Sharing flaw that could let an attacker on the network authenticate without valid credentials. Apple’s security advisory confirms the update arrived on August 6 and fixes CVE-2026-65400.
Apple describes it as an authentication issue and says improved state management fixed it. The public CVE record classifies the flaw as improper authentication, while CISA’s enrichment gives it a 7.1 High severity score.
The advisory does not say the flaw has been exploited in the wild. Apple credits Alfredo Pesoli via Bynario Atlas for reporting it.
Sequoia and Sonoma get the same fix
If your Mac does not support macOS Tahoe 26, Apple has also released macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. Both updates patch the same Screen Sharing vulnerability.
Apple’s CVE record lists versions earlier than Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 as affected. That means staying on the previous 26.6, 15.7.8, or 14.8.8 release leaves the bug unpatched.
Update now or turn off Screen Sharing temporarily
Open System Settings > General > Software Update and install the update offered for your Mac. Apple lists Tahoe 26.6.1 as the latest macOS release, and this point update is focused on security rather than new features.
The risk matters because the built-in Screen Sharing feature can give another computer access to view and control your Mac. If you cannot update immediately and do not need the feature, open System Settings > General > Sharing and turn off Screen Sharing until the patch is installed.
Macs managed by a workplace or school may have different remote-access settings. In that case, follow your administrator’s instructions rather than changing a managed setting yourself.



