Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

0
Medium
Exploitmacos
Published: 08/17/2026 (08/17/2026, 08:47:38 UTC)
Source: SecurityWeek

Description

Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek .

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 08:56:22 UTC

Technical Analysis

CVE-2026-65400 is a high-severity authentication bypass vulnerability in macOS Screen Sharing that allows remote attackers to authenticate without valid credentials by simply specifying a username. This flaw enables attackers to gain root access on vulnerable systems. Apple addressed this vulnerability in updates released on August 6, 2026, for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The Dutch National Cyber Security Centrum reported active exploitation in the wild shortly after patch release, with attackers deploying Monero miners on compromised systems. The vulnerability affects macOS systems with Screen Sharing enabled and port 5900 accessible from the internet. Additional severe vulnerabilities in the Screen Sharing daemon were also patched recently, including an unauthenticated remote code execution flaw that allowed root-level compromise without user interaction. The exposure risk was heightened by the presence of approximately 40,000 internet-accessible macOS systems with Screen Sharing enabled prior to patching.

Potential Impact

Successful exploitation allows remote attackers to bypass authentication and gain root access on vulnerable macOS systems. Attackers have used this access to deploy Monero cryptocurrency miners, indicating unauthorized resource usage and potential system compromise. The vulnerability affects systems with Screen Sharing enabled and accessible from the internet, increasing the risk of widespread exploitation. The presence of additional related vulnerabilities in the Screen Sharing daemon further elevates the risk of remote code execution and full system takeover.

Mitigation Recommendations

Apple has released official patches for this vulnerability in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Applying these updates promptly is the primary mitigation. Systems with Screen Sharing enabled and exposed to the internet should be updated immediately. Additionally, restricting access to port 5900 from untrusted networks can reduce exposure. The vendor manages remediation for this vulnerability through these updates; no other temporary fixes or workarounds are indicated. Users should verify that SIP (System Integrity Protection) is enabled to reduce risk from related vulnerabilities.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.69,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/recent-macos-screen-sharing-vulnerability-exploited-in-attacks/","fetched":true,"fetchedAt":"2026-08-17T08:56:13.919Z","wordCount":1056}

Threat ID: 6a82ccadbf8831d53990ca0a

Added to database: 08/17/2026, 08:56:13 UTC

Last enriched: 08/17/2026, 08:56:22 UTC

Last updated: 08/18/2026, 09:45:06 UTC

Views: 91

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses