Patched macOS Screen Sharing Flaw Under Active Exploitation, Root Access Confirmed

Patched macOS Screen Sharing Flaw Under Active Exploitation, Root Access Confirmed

CVE-2026-65400, a macOS Screen Sharing authentication bypass, is being actively exploited. The Dutch NCSC reported attackers gaining root access and deploying Monero miners on multiple systems. Apple shipped patches on August 6 (macOS 26.6.1, 15.7.9, 14.8.9) covering Tahoe, Sequoia, and Sonoma. Exploitation requires exposed port 5900; administrators should patch and close it.

Published

Read at another depth