Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
CVEIncidentMac

macOS Screen Sharing CVE: Active Exploitation Confirmed for Root Access and Crypto Mining

By ogwatermelon
August 15, 2026 3 Min Read
0
August 14, 2026

The Netherlands’ National Cyber Security Centre (NCSC) has confirmed active exploitation of CVE-2026-65400, a macOS Screen Sharing authentication bypass vulnerability. Attackers with network access to TCP port 5900 can gain root access without valid credentials and deploy Monero cryptocurrency miners on affected systems.

What Happened: macOS Screen Sharing Authentication Bypass Enables Root Access

Apple patched CVE-2026-65400 on August 6, 2026, in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The flaw resides in macOS Screen Sharing, a built-in remote desktop feature that uses the VNC protocol over TCP port 5900. Consequently, the vulnerability allows network-based attackers to bypass authentication entirely.

The NCSC updated its advisory on August 12 after receiving reports of active exploitation. In all observed incidents, attackers obtained root access and installed Monero cryptocurrency mining malware. Moreover, the attacks targeted systems with port 5900 exposed to the internet.

Technical Details of the macOS Screen Sharing Vulnerability

CVE-2026-65400 stems from improper state management during the Screen Sharing authentication process. The flaw allows rogue authentication attempts to succeed without valid credentials.

The attack prerequisites are:

  • macOS system with Screen Sharing enabled
  • TCP port 5900 accessible from the attacker’s network position
  • No valid credentials required for exploitation

Furthermore, an attacker exploiting this flaw can perform the following actions remotely:

  • Open applications on the target system
  • Access and exfiltrate files
  • Modify security settings
  • Execute arbitrary commands with root privileges

Monero Miner Deployment

In confirmed attacks, threat actors used the root access to deploy Monero cryptocurrency mining software. Monero is favored by attackers because its transactions are difficult to trace. The mining operation consumes CPU and GPU resources, degrading system performance and increasing electricity costs.

Business and Operational Impact

The exploitation of CVE-2026-65400 carries significant consequences for affected organizations and individuals.

  • Unauthorized remote control: Attackers gain full administrative access to macOS systems
  • Data exposure: Files, credentials, and sensitive information become accessible
  • Resource theft: Cryptocurrency mining consumes computing resources
  • Lateral movement: Compromised systems can serve as pivot points
  • Compliance violations: Unauthorized access may trigger regulatory reporting

Moreover, macOS devices are commonly deployed in creative industries, software development, and executive environments. Therefore, this vulnerability poses a elevated risk in environments where macOS is prevalent.

Mitigation and Recommendations

Immediate Actions for Defenders

  1. Apply Apple security updates immediately:
    • macOS Tahoe 26.6.1
    • macOS Sequoia 15.7.9
    • macOS Sonoma 14.8.9
  2. Disable Screen Sharing if not required
  3. Restrict TCP port 5900 access using network firewalls
  4. Monitor for unusual CPU and network activity

Additional Hardening Steps

Organizations should also consider the following measures:

  • Implement network segmentation for remote desktop services
  • Enable firewall rules blocking port 5900 from external networks
  • Review logs for unauthorized Screen Sharing sessions
  • Scan for cryptocurrency mining indicators

Bottom line: CVE-2026-65400 is actively exploited in the wild. Patch immediately. Disable Screen Sharing if unused. Block TCP port 5900 from internet exposure.

Incident Summary

CVE ID: CVE-2026-65400
Affected Systems: macOS Screen Sharing (Tahoe, Sequoia, Sonoma)
Disclosure Date: August 7, 2026 (NCSC-2026-0280)
Patch Status: Available — macOS Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9
Attack Vector: Network, TCP port 5900
Exploitation: Active — root access and Monero miner deployment confirmed

References

  1. NCSC Netherlands, “Security Advisory NCSC-2026-0280 — Kwetsbaarheid verholpen in macOS Screen Sharing door Apple,” August 12, 2026. https://advisories.ncsc.nl/2026/ncsc-2026-0280.html
  2. Apple Inc., “About the security content of macOS Tahoe 26.6.1,” August 6, 2026. https://support.apple.com/en-us/148170
  3. Apple Inc., “About the security content of macOS Sequoia 15.7.9,” August 6, 2026. https://support.apple.com/en-us/148171
  4. BleepingComputer, “Hackers exploit macOS Screen Sharing flaw to deploy Monero miner,” August 14, 2026. https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/

Tags:

CVEMacVulnerability
Author

ogwatermelon

Follow Me
Other Articles
Previous

Plug and Pwn Attack: Fake USB Devices Hijack Windows Plug and Play for SYSTEM Privileges

Next

SAP Commerce Cloud Unauthenticated RCE Under Active Exploitation Days After Patch

AI Botnet Breach CVE Exploit Hack Incident Infostealer Linux Mac Malware Network Phishing Ransomware RCE supply chain Vishing Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Infostealer
  • Linux
  • Mac
  • Malware
  • Phishing
  • Ransomware
  • RCE
  • supply-chain
  • Uncategorized
  • Vishing
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.