On 6 August 2026, Apple released macOS Tahoe 26.6.1 to fix a single security flaw — but it is a serious one. The vulnerability allowed an attacker on the same network to authenticate to a Mac's Screen Sharing service without valid credentials.
Apple issued the same fix for two older systems, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9, which tells you something about how seriously it was treated. If you have not updated since early August, do it before you finish reading this.
The flaw is tracked as CVE-2026-65400. In Apple's own wording, the impact is that "an attacker on the network may be able to authenticate to Screen Sharing without valid credentials", and it was resolved by addressing "an authentication issue" with "improved state management".
Security firm Huntress has described the underlying problem as a bug in how the Screen Sharing service implements Secure Remote Password, the protocol that is supposed to prove you know the password without sending it. Huntress assesses that the flaw permits pre-authenticated remote code execution on affected macOS versions.
That phrase is worth unpacking, because it is the difference between an annoyance and a genuine problem:
Apple credits the discovery to Alfredo Pesoli via Bynario Atlas. There is no public indication the flaw was exploited in the wild before the patch, which is the one genuinely reassuring detail here.
The qualifier "an attacker on the network" is the key limitation. This is not something a random person on the internet can reach on a typical home connection sitting behind a router. The realistic risk scenarios are:
For a business running a room full of Macs with Remote Management switched on for IT support — a very common arrangement — this is exactly the kind of flaw worth acting on promptly.
On the Mac, open System Settings, then General, then Software Update. Install whichever of these applies to you:
These are small security releases rather than feature updates, so they install quickly and change nothing about how your Mac works. There is no sensible reason to defer one.
While you are in Software Update, click the small information icon beside Automatic Updates and confirm that "Install Security Responses and system files" is switched on. That setting is what gets rapid fixes onto your Mac without you having to read an article like this one first.
Many people have Screen Sharing enabled from a support session years ago and have never turned it off. It is worth two minutes to check.
Go to System Settings, then General, then Sharing. Look at Screen Sharing and Remote Management. If you do not actively need either, switch them off. If you do need them, make sure access is restricted to specific users rather than all users, and that those accounts have strong, unique passwords.
Turning off a service you do not use is the most reliable security measure available, because a service that is not running cannot be attacked. Patching matters, but reducing what is exposed in the first place matters more.
Apple issued this fix for macOS Sonoma, Sequoia and Tahoe. If your Mac is running something older — Ventura or earlier — it did not receive a patch, and it is presumably vulnerable.
In that situation, disabling Screen Sharing and Remote Management is not optional housekeeping, it is the mitigation. Beyond that, an older Mac stuck on an unsupported macOS version is worth a conversation about whether it can be upgraded to a newer one, or whether it is time to replace it.
Sometimes the limitation is genuinely the hardware. Often it is a machine that could run a newer macOS comfortably with more memory or a modern SSD; our SSD upgrades listed by Mac model cover most Intel-era machines. If the Mac cannot go any further, our certified refurbished Macs are a lower-cost way onto a currently supported system.
For businesses with several Macs to check and patch, our IT services team can audit which machines are exposed and bring them up to date. If a single Mac is behaving oddly and you would rather have someone look at it, our Melbourne Mac repair service is the place to start.
A serious Screen Sharing authentication flaw was patched on 6 August 2026 across macOS Tahoe, Sequoia and Sonoma. It requires network access rather than being remotely exploitable from anywhere, and there is no evidence it was used before the fix shipped. Update your Mac, and while you are there, turn off Screen Sharing if you are not using it.