Published · 6d agoProduct3 min read
Apple's quiet Screen Sharing fix is now a same-day job: CVE-2026-65400 is under active abuse
Dutch officials report root access and Monero miners on Macs with port 5900 open to the internet. Sonoma, Sequoia and Tahoe all need the update Apple shipped as an important security fix.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Earlier this month Apple released macOS Sonoma 14.8.9, macOS Sequoia 15.7.9 and macOS Tahoe 26.6.1, with release notes initially stating only that they provided "important security fixes" and were recommended for all users.
- Apple later expanded the advisory: Impact - "An attacker on the network may be able to authenticate to Screen Sharing without valid credentials"; Description - "An authentication issue was addressed with improved state management."
- The vulnerability is tracked as CVE-2026-65400, carries a severity rating of 7.1 out of 10, and received a patch from Apple last week for macOS Tahoe, Sequoia and Sonoma.
- The Netherlands National Cyber Security Centrum warned earlier this week: "The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet... In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed."
- At the time of the updates, Apple said there was no evidence of the vulnerability being exploited in the wild; that is no longer the case.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Apple shipped macOS Sonoma 14.8.9, Sequoia 15.7.9 and Tahoe 26.6.1 earlier this month behind release notes that said only that they contained important security fixes recommended for all users [1]. The bug those updates closed, tracked as CVE-2026-65400, is now being exploited: the Netherlands National Cyber Security Centrum said earlier this week that it had been notified of active abuse on multiple systems where port 5900 was reachable from the internet, and that in every case root was obtained and a Monero crypto miner planted [3][4].
Apple's expanded advisory is two lines: an attacker on the network may be able to authenticate to Screen Sharing without valid credentials, and the underlying authentication issue was addressed with improved state management [2]. Ars Technica puts the severity at 7.1 out of 10 and describes the root cause as a flaw in the state management that tracks preceding events, user interactions and variables [3][7]. Screen Sharing lets a remote party view the screen and drive the keyboard and mouse on a running machine [6], which 9to5Mac notes gives an attacker roughly what physical possession of a logged-in Mac would [10].
Two details make this a different kind of patch cycle than the release notes implied. First, Apple said at the time of release that there was no evidence of exploitation in the wild [5], and that statement is now stale. Second, the details of the vulnerability became public at Black Hat last week [8], and the NCSC notification came within days [4] - roughly a week between public disclosure and observed root-level compromise [14]. Ars Technica also reports that video of the exploit in action is available [12], and that Apple hedged with language saying the flaw "may" allow an uncredentialed attacker in, which Ars calls common softening in vendor disclosures [9].
Apple's phrase "an attacker on the network" reads differently against the reported cases, where the affected hosts had 5900 exposed to the open internet [13]. That is the practical scoping question for a fleet: not just which Macs are unpatched, but which ones answer on 5900 from outside. The identical payload across multiple victims points to scanning-driven opportunism rather than targeting [16], which means exposure alone is the qualifying criterion. Screen Sharing is toggled under System Settings > General > Sharing, and 9to5Mac's advice is to enable it only for the duration of a session and switch it off afterwards [11].
What to watch: whether other national CERTs confirm abuse independently of the NCSC report, which is currently the single source for exploitation [4]; whether observed payloads move past mining toward credential theft, which 9to5Mac flags as the obvious next step [15]; and whether Apple restates the advisory now that the no-evidence line from release week no longer holds [5].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Earlier this month Apple released macOS Sonoma 14.8.9, macOS Sequoia 15.7.9 and macOS Tahoe 26.6.1, with release notes initially stating only that they provided "important security fixes" and were recommended for all users.
ReportedView cited source - [2]
Apple later expanded the advisory: Impact - "An attacker on the network may be able to authenticate to Screen Sharing without valid credentials"; Description - "An authentication issue was addressed with improved state management."
ReportedView cited source - [3]
The vulnerability is tracked as CVE-2026-65400, carries a severity rating of 7.1 out of 10, and received a patch from Apple last week for macOS Tahoe, Sequoia and Sonoma.
ReportedView cited source - [4]
The Netherlands National Cyber Security Centrum warned earlier this week: "The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet... In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed."
ReportedView cited source - [5]
At the time of the updates, Apple said there was no evidence of the vulnerability being exploited in the wild; that is no longer the case.
ReportedView cited source - [6]
The macOS screen sharing capability allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on.
ReportedView cited source
Sources & coverage · 5 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- arstechnica.comDan GoodinAug 14Vulnerability giving attackers full control of Macs is under active exploitation
- 9to5mac.comBen Lovejoy6d agoA serious Mac screen sharing vulnerability is being actively exploited
- macrumors.comTim Hardwick



