Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Reported exploitedmacOS Screen SharingOur summary
Attackers are actively leveraging CVE-2026-65400, a high-severity authentication bypass in Apple's macOS Screen Sharing feature, to seize root privileges and deploy cryptocurrency miners. The vulnerability allows remote adversaries to authenticate without valid credentials by simply specifying an existing account name, a method made easier by public proof-of-concept exploits. Apple addressed this defect in updates released on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, alongside other fixes for the screensharingd daemon.
The Dutch NCSC confirmed in-the-wild abuse targeting systems with port 5900 open to the internet, warning that approximately 40,000 exposed devices remain vulnerable. Administrators should ensure all macOS instances are patched and restrict unnecessary external access to Screen Sharing ports.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.