Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer
Attackers actively exploit patched macOS Screen Sharing bug CVE-2026-65400 on systems with port 5900 exposed, gaining root to install a Monero cryptominer.
The Netherlands' National Cyber Security Centre (NCSC) reports active exploitation of CVE-2026-65400, an authentication flaw in macOS Screen Sharing that lets attackers authenticate without valid login credentials. Apple patched the issue in macOS Sequoia 15.7.9, Sonoma 14.8.9 and Tahoe 26.6.1, and the NCSC escalated its advisory on August 12 after proof-of-concept code went public and reports arrived of attacks on internet-exposed systems. In every reported case attackers obtained root access and installed a Monero crypto miner; users who cannot patch immediately are advised to disable Screen Sharing.
- Exploitation observed after PoC code went public; NCSC raised advisory severity on August 12
- All reported victims had Screen Sharing (port 5900) reachable from the internet
- Flaw reported by researcher Alfredo Pesoli (@__rev) of Bynario Atlas
- Mitigations: update to fixed macOS versions or disable Screen Sharing
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-65400 | Authentication Bypass in Apple macOS Screen Sharing CVE-2026-65400 is a critical (CVSS 9.8) improper authentication flaw (CWE-287) in Apple macOS's Screen Sharing service, caused by an authentication state-management defect. An attacker who can reach a vulnerable Mac's Screen Sharing service over the network can authenticate without valid credentials, gaining full remote access with high impact to confidentiality, integrity, and availability. All three currently supported macOS branches are affected: Sequoia, Sonoma, and Tahoe, in versions prior to the fixed releases. The flaw is being actively exploited on the internet, with public reporting that attackers use the bypass to deploy Monero cryptominers, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-18. EPSS estimates a 9.9% probability of exploitation within 30 days (95th percentile). Do: Upgrade to macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, or macOS Tahoe 26.6.1 (or later) immediately; patching is mandatory for federal agencies under CISA BOD 26-04 given the KEV listing. As an interim mitigation, disable Screen Sharing or restrict it via firewall/VPN so VNC (port 5900) is not reachable from the internet. Review internet-exposed Macs for signs of compromise, especially unexplained Monero miner processes or abnormal CPU usage. | 9.8 | 10% | KEV |
| masson the order of 100M+ Macs run affected macOS versions; the directly exploitable subset is Macs with Screen Sharing enabled and internet-reachable |
Full article266 words · extracted from helpnetsecurity.com · click to collapse
A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns.

The vulnerability, tracked as CVE-2026-65400, , let attackers authenticate to macOS Screen Sharing without valid login credentials.
Apple fixed the issue with updates to macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1), and advised its macOS users to upgrade their systems.
“An authentication issue was addressed with improved state management,” Apple said in its advisory, crediting researcher Alfredo Pesoli, known as @__rev of Bynario Atlas, for reporting the issue.
On August 7, one day after Apple’s fix, the NCSC published its first advisory, urging organizations to update. The warning was informational, since no exploitation had been reported at that point. That changed five days later, on August 12, when the agency raised the advisory’s severity after proof-of-concept code went public and reports of active attacks on exposed systems began arriving.
“NCSC has received a report indicating active exploitation of this vulnerability has been observed on multiple systems where port 5900 was reachable from the internet. In all these cases, root access was obtained on the affected system and a Monero crypto miner was installed,” NCSC wrote.
Users who can’t patch immediately can disable Screen Sharing manually, by opening System Settings, selecting General, then Sharing, and switching the Screen Sharing toggle off.
NCSC hasn’t shared details on the scope of the attacks, including when they started, how many systems were hit, or whether attackers did anything beyond installing the cryptominer.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/17/apple-macos-screen-sharing-flaw/