Overview
- Apple issued out-of-band fixes for CVE-2026-65400 on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9, and users should install those updates immediately.
- The Netherlands’ NCSC-NL confirmed active exploitation of the Screen Sharing bug that in reported cases allowed attackers to obtain root on internet-facing Macs and install Monero miners.
- CISA rescored the vulnerability to 9.8 on August 14 and marked it automatable, reflecting that exploits now require no privileges or user interaction to succeed.
- Security researchers report tens of thousands of Macs with TCP port 5900 exposed to the internet, with hosted bare-metal Mac services especially at risk because providers sometimes enable Screen Sharing by default.
- The flaw is a pre-authentication state-management bypass of the Secure Remote Password flow, so changing Screen Sharing passwords does not stop attacks and only Apple’s patch or disabling Screen Sharing fully mitigates the issue.