Overview
- Apple released an out‑of‑band fix for CVE‑2026‑65400 on August 6 that corrected improper state management in the Screen Sharing authentication flow.
- The Netherlands’ NCSC updated its advisory on August 12 to report active exploitation where attackers gained root on internet‑reachable Macs and installed Monero miners.
- CISA raised the vulnerability’s score to 9.8 and labeled the flaw automatable after public proof‑of‑concept code and rapid weaponization were observed.
- Practical risk requires Screen Sharing to be enabled and port 5900 reachable from the internet so hosted or port‑forwarded Macs are at highest exposure.
- The only reliable defenses are installing Apple’s security updates or disabling Screen Sharing and blocking TCP/5900 until systems are patched because password resets do not stop this pre‑authentication bypass.