
Apple released urgent security updates for macOS Tahoe, Sequoia, and Sonoma on August 6, 2026. The updates fix CVE-2026-65400, a Screen Sharing authentication flaw that Apple says could let an attacker on the network authenticate without valid credentials.
The short version
- Install: macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9—whichever your Mac offers.
- Why: the patch closes a Screen Sharing authentication bypass reachable by an attacker on the network.
- Extra caution: if you do not use Screen Sharing or Remote Management, turn those services off while you verify and deploy the update.
- Exploit status: Apple’s advisories do not say the flaw is actively exploited. That is not the same as saying exploitation is impossible.
Which macOS updates were released?
Apple published a separate security advisory for each currently supported macOS line. All three name the same Screen Sharing vulnerability and the same August 6 release date.
Phone readers: swipe the table left to see every version, build, and CVE column.
| Mac operating system | Install this version | Build | Security fix |
|---|---|---|---|
| macOS Tahoe | 26.6.1 | 25G76 | CVE-2026-65400 |
| macOS Sequoia | 15.7.9 | 24G830 | CVE-2026-65400 |
| macOS Sonoma | 14.8.9 | 23J631 | CVE-2026-65400 |
What the Screen Sharing flaw means
Screen Sharing lets another device view or control a Mac’s desktop when the service is enabled and the connection is authorized. Apple’s wording for CVE-2026-65400 is direct: “An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.” Apple says it corrected the authentication issue with improved state management.
The important boundary is “on the network.” Apple does not describe this advisory as an internet-wide, zero-click compromise. Risk is more immediate on untrusted or shared networks, poorly segmented business networks, or any setup where Screen Sharing is exposed farther than intended. A firewall or router that blocks unsolicited inbound traffic helps, but it does not replace the patch—especially when an attacker has already reached the same network through Wi-Fi, VPN access, a compromised device, or a misconfiguration.
Do not overstate the alert
Apple has not labeled CVE-2026-65400 as actively exploited in these advisories. It also did not publish a CVSS score on the cited pages. This is a meaningful authentication-bypass patch, not proof that every Mac has already been attacked.
How to check whether your Mac is affected
- Open the Apple menu in the upper-left corner.
- Select About This Mac, or open System Settings → General → About.
- Read the macOS version and build number.
- If the Mac is on Tahoe 26.6 or earlier, Sequoia 15.7.8 or earlier, or Sonoma 14.8.8 or earlier, install the offered update.
- After the restart, return to About and confirm the installed version matches the table above.
If your Mac runs an older branch that is not listed, do not assume that “not listed” means “not affected.” It means Apple’s August 6 release ledger does not provide one of these three packages for that branch. Check Software Update, confirm whether the Mac can upgrade to a supported macOS version, and make a replacement or isolation plan for hardware that cannot.
How to install the update safely
- Save your work and close important applications.
- Verify a current backup. Time Machine is useful, but a business should also confirm that critical files and line-of-business data exist in a tested backup outside the Mac.
- Connect a MacBook to power and use a stable network.
- Open System Settings → General → Software Update.
- Install the version offered for your supported macOS branch. Do not download an “updater” from an advertisement, pop-up, or third-party download site.
- Restart if prompted, then verify the new version and build.
If Software Update does not show the expected version immediately, wait a short time, refresh the panel, and confirm that the Mac is not controlled by a business update-deferral policy. Do not disable management controls blindly; ask the administrator responsible for that policy.
Check Screen Sharing and Remote Management now
On a current Mac, open System Settings → General → Sharing. Review both Screen Sharing and Remote Management. If neither is needed, turn them off. If one is required, limit access to named users rather than broad groups, and avoid exposing the service directly to the public internet.
Also review third-party remote-access tools. Apple Screen Sharing is not the only way a Mac can be remotely controlled, and an old support agent can quietly remain installed after a vendor or employee no longer needs access. Use our 30-minute remote-support software audit to check for forgotten tools and stale access.
Home-user actions
- Install the update tonight or at the next safe restart window.
- Turn off Screen Sharing if you never use it.
- Use a strong, unique Mac login password and do not approve unexpected remote-control prompts.
- Keep the Mac behind a properly configured home router; avoid exposing management ports to the internet.
- Check every supported Mac in the household—not just the one you use most.
Business and IT actions
- Inventory first: identify Tahoe, Sequoia, and Sonoma devices, their current builds, and which devices have Screen Sharing or Remote Management enabled.
- Prioritize exposure: patch Macs used on shared networks, remote-worker networks, labs, classrooms, reception areas, and support environments first.
- Use MDM: deploy the correct update through your existing management workflow and watch installation compliance.
- Stage intelligently: test a small representative group for critical application, VPN, printing, security-agent, and peripheral compatibility—but do not turn a routine pilot into an open-ended delay.
- Reduce reachability: restrict remote-management traffic to approved management networks or a properly secured VPN.
- Document exceptions: record any device that cannot update, why, its compensating controls, owner, and replacement deadline.
Good points and cautions
Good
- Apple patched all three supported macOS lines on the same day.
- The remediation is delivered through normal Software Update.
- Apple clearly identifies the affected component and CVE.
- Administrators can reduce risk further by limiting or disabling unneeded sharing services.
Cautions
- Authentication bypasses can undermine the control users expect a password to provide.
- Network reachability may be broader than an owner realizes.
- Older Macs outside the listed branches need a separate support and upgrade review.
- Apple’s short advisories do not provide a public list of application-compatibility issues for these maintenance releases.
Known issues and what Apple has not said
Apple’s three security advisories focus on the Screen Sharing fix and do not list known issues. The Tahoe 26.6.1 update note says the update provides security fixes for the Mac. Absence of a known-issues list is not a promise that every third-party application or peripheral will behave identically, so businesses should still use a short, representative pilot and verify backups.
Apple also does not say in these advisories that CVE-2026-65400 is actively exploited, publicly disclosed before release, or remotely reachable from anywhere on the internet. Keep those distinctions intact when sharing the alert.
What about Windows tonight?
Our August 6 sweep found no same-day Windows production cumulative update, out-of-band Windows patch, or new Windows release-health incident requiring user action. Microsoft did publish its August “early security updates,” but the entries were cloud-service disclosures that Microsoft says were already mitigated and required no customer action. A same-day revision to the July security document updated an acknowledgement only; it did not change a Windows fix, severity, exploitation status, or deployment requirement.
The latest Windows production security updates remain the July 14 releases, while late-July Windows 11 updates were previews. Do not confuse preview or Insider builds with today’s Apple production security release.
FAQ
Is CVE-2026-65400 a zero-day?
Apple’s advisories do not say it was actively exploited or publicly known before the patch. Based on the official information available tonight, we are not labeling it a zero-day.
Am I safe if Screen Sharing is off?
Turning off an unused service reduces exposure, but it is not a reason to skip the update. Configurations change, other administrators may enable the service later, and the patch is the durable correction Apple provides.
Does this affect Apple Remote Desktop?
Apple names the affected component as Screen Sharing. Because Remote Management can also permit remote screen control, administrators should review both settings and follow their MDM and Apple Remote Desktop guidance rather than assuming one label makes the Mac unaffected.
Should I update before making a backup?
For most users, take a current backup first if one is not already available, then update promptly. A tested backup protects against unrelated storage, power, or compatibility problems during any operating-system maintenance.
What if my Mac cannot run Sonoma, Sequoia, or Tahoe?
Treat that as a support-lifecycle issue. Check for any update Apple still offers, limit remote access, isolate the device from sensitive networks where practical, and plan an upgrade or replacement. “No update offered” does not prove the older Mac is safe.
Need help checking or updating business Macs?
The IT Guys serves Port Saint Lucie, Jensen Beach, Fort Pierce, and Vero Beach. We can help verify versions, review remote-access exposure, check backups, and plan a controlled rollout. See our services or contact The IT Guys.
Official sources
- Apple: About the security content of macOS Tahoe 26.6.1
- Apple: About the security content of macOS Sequoia 15.7.9
- Apple: About the security content of macOS Sonoma 14.8.9
- Apple security releases index
- Apple: What’s new in updates for macOS Tahoe
- Microsoft Security Response Center update index
- Windows message center
Checked and published August 6, 2026, at approximately 7 PM Eastern. Vendor pages can be revised after publication; always recheck Software Update or your management console before deployment.
