The Netherlands’ National Cyber Security Centre (NCSC) has confirmed active exploitation of CVE-2026-65400, a macOS Screen Sharing authentication bypass vulnerability. Attackers with network access to TCP port 5900 can gain root access without valid credentials and deploy Monero cryptocurrency miners on affected systems.
What Happened: macOS Screen Sharing Authentication Bypass Enables Root Access
Apple patched CVE-2026-65400 on August 6, 2026, in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The flaw resides in macOS Screen Sharing, a built-in remote desktop feature that uses the VNC protocol over TCP port 5900. Consequently, the vulnerability allows network-based attackers to bypass authentication entirely.
The NCSC updated its advisory on August 12 after receiving reports of active exploitation. In all observed incidents, attackers obtained root access and installed Monero cryptocurrency mining malware. Moreover, the attacks targeted systems with port 5900 exposed to the internet.
Technical Details of the macOS Screen Sharing Vulnerability
CVE-2026-65400 stems from improper state management during the Screen Sharing authentication process. The flaw allows rogue authentication attempts to succeed without valid credentials.
The attack prerequisites are:
- macOS system with Screen Sharing enabled
- TCP port 5900 accessible from the attacker’s network position
- No valid credentials required for exploitation
Furthermore, an attacker exploiting this flaw can perform the following actions remotely:
- Open applications on the target system
- Access and exfiltrate files
- Modify security settings
- Execute arbitrary commands with root privileges
Monero Miner Deployment
In confirmed attacks, threat actors used the root access to deploy Monero cryptocurrency mining software. Monero is favored by attackers because its transactions are difficult to trace. The mining operation consumes CPU and GPU resources, degrading system performance and increasing electricity costs.
Business and Operational Impact
The exploitation of CVE-2026-65400 carries significant consequences for affected organizations and individuals.
- Unauthorized remote control: Attackers gain full administrative access to macOS systems
- Data exposure: Files, credentials, and sensitive information become accessible
- Resource theft: Cryptocurrency mining consumes computing resources
- Lateral movement: Compromised systems can serve as pivot points
- Compliance violations: Unauthorized access may trigger regulatory reporting
Moreover, macOS devices are commonly deployed in creative industries, software development, and executive environments. Therefore, this vulnerability poses a elevated risk in environments where macOS is prevalent.
Mitigation and Recommendations
Immediate Actions for Defenders
- Apply Apple security updates immediately:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
- Disable Screen Sharing if not required
- Restrict TCP port 5900 access using network firewalls
- Monitor for unusual CPU and network activity
Additional Hardening Steps
Organizations should also consider the following measures:
- Implement network segmentation for remote desktop services
- Enable firewall rules blocking port 5900 from external networks
- Review logs for unauthorized Screen Sharing sessions
- Scan for cryptocurrency mining indicators
Bottom line: CVE-2026-65400 is actively exploited in the wild. Patch immediately. Disable Screen Sharing if unused. Block TCP port 5900 from internet exposure.
Incident Summary
| CVE ID: | CVE-2026-65400 |
| Affected Systems: | macOS Screen Sharing (Tahoe, Sequoia, Sonoma) |
| Disclosure Date: | August 7, 2026 (NCSC-2026-0280) |
| Patch Status: | Available — macOS Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9 |
| Attack Vector: | Network, TCP port 5900 |
| Exploitation: | Active — root access and Monero miner deployment confirmed |
References
- NCSC Netherlands, “Security Advisory NCSC-2026-0280 — Kwetsbaarheid verholpen in macOS Screen Sharing door Apple,” August 12, 2026. https://advisories.ncsc.nl/2026/ncsc-2026-0280.html
- Apple Inc., “About the security content of macOS Tahoe 26.6.1,” August 6, 2026. https://support.apple.com/en-us/148170
- Apple Inc., “About the security content of macOS Sequoia 15.7.9,” August 6, 2026. https://support.apple.com/en-us/148171
- BleepingComputer, “Hackers exploit macOS Screen Sharing flaw to deploy Monero miner,” August 14, 2026. https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/