Apple Mac Screen Sharing Flaw CVE-2026-65400 Exploited to Install Monero Miners
The Netherlands National Cyber Security Centre (NCSC-NL) reports active exploitation of CVE-2026-65400, a macOS Screen Sharing authentication flaw rated 9.8 by the National Vulnerability Database, on Macs with port 5900 exposed to the internet. In each reported case, attackers gained root access and installed a Monero cryptocurrency miner, according to the agency. Apple patched the flaw on 6 August in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. Gadgets 360 cited a lower severity score of 7.1, a disagreement the sources do not resolve.
Bottom line — Apple's patched Screen Sharing flaw is being used by attackers against Macs left exposed to the internet, with Microsoft reporting root logins on a limited number of devices.
Go deeper 6
-
Microsoft said on 18 August it had observed exploitation on a 'limited number of macOS devices', with attackers copying scripts and an SSH key, establishing persistence and disguising the XMRig miner as an Apple process.
-
The Hacker News reported that security researcher Alfredo Pesoli of Bynario discovered and reported the flaw, which Apple credited in its advisory.
-
Calif, an AI security company, said it produced a working exploit for two related pre-authentication flaws in four hours with an AI agent, and is withholding details until most users are upgraded.
-
The Hacker News cited researcher @osxreverser estimating around 40,000 open Screen Sharing hosts on the internet, almost half in the US, though this is a single researcher's scan figure.
-
Bitdefender's Hot for Security advises that patching does not remove an intrusion already made, and recommends erasing and reinstalling macOS on affected machines rather than just removing the visible miner.
-
NCSC-NL has not disclosed how many systems were compromised, when the attacks began, or whether other malware was deployed.