Build1 publisher3 min readPublished Updated
Unauthenticated root on macOS Screen Sharing: CVE-2026-65400 is already dropping miners
An authentication state flaw lets anyone who reaches TCP/5900 skip credentials entirely. Multiple cases reported to NCSC-NL ended in root and a Monero miner.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- A dev.to article dated 2026-08-14 summarises a BleepingComputer report headlined "Hackers exploit macOS Screen Sharing flaw to deploy Monero miner" and rates the issue Critical.
- CVE-2026-65400 is an authentication state management flaw in macOS Screen Sharing exposed to the internet that allows attackers to authenticate without valid credentials.
- The attacker connects to macOS Screen Sharing from the internet via TCP/5900 and exploits the authentication state flaw to establish a session without valid credentials; initial execution occurs within the Screen Sharing service and the remote GUI session.
- The attacker gains the ability to launch applications, access files, and change security settings via remote desktop.
- In multiple cases reported to NCSC-NL, the attacker obtained root access.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
A dev.to writeup dated 2026-08-14, summarising a BleepingComputer report, describes CVE-2026-65400 as an authentication state management flaw in macOS Screen Sharing that lets an attacker reaching the service over the internet establish a session without valid credentials [1][2][3]. In multiple cases reported to the Dutch NCSC, that session ended in root access and the installation of a Monero cryptocurrency miner [5][6].
The chain is short enough to fit in a sentence: connect to TCP/5900 from the internet, exploit the state flaw, get a remote desktop session with the ability to launch applications, read files, and change security settings [3][4]. No user interaction is required, so there is no phishing step to detect and no click to blame [8]. The preconditions are unglamorous and common: Screen Sharing enabled, TCP/5900 reachable by the attacker, patches not applied, and nothing in place to constrain execution or settings changes once a remote session exists [10]. That is a description of a lot of Mac minis and desk machines that someone port-forwarded for convenient out-of-office access.
Two operational details matter more than the CVE number. First, because valid accounts are never used, a password reset alone cannot contain the intrusion, and sessions persisting after a password change are themselves a signal worth hunting [9][19]. Second, the fix spans three separate release trains: macOS Tahoe before 26.6.1, Sequoia before 15.7.9, and Sonoma before 14.8.9 are affected, so a patch audit has to cover three version baselines rather than one [7][21]. MDM device version and compliance data is the practical way to check that state at fleet scale [18].
Containment does not depend on the details being published. Update to the fixed builds, disable Screen Sharing where it is not needed, and block TCP/5900 from the internet, restricting it to VPN or management networks [7][11]. For hunting, the listed signals are TCP/5900 connections from external IPs, Screen Sharing sessions not tied to regular accounts, unknown binaries running as root, elevated CPU or GPU usage, and outbound traffic or DNS queries to mining pools and Stratum endpoints [14][15]. Connections from a single source IP to multiple Macs, and miner pool traffic that follows a session, are the higher-confidence patterns; bare TCP/5900 scanning or SYN traffic is not [16]. If you find a hit, the triage list is standard: confirm macOS version, Screen Sharing settings, exposure path, initial source IP and timestamp, cross-reference session logs against valid login activity, and preserve process trees, launchd entries, file creations, quarantine and xattr attributes, unified logs, and network sockets [17].
Be honest about the gaps. The specific steps used to reach root, whether other vulnerabilities are involved, and how the miner persists are not publicly disclosed, and the miner's name and hash are unknown [12][6]. Data theft and lateral movement are not confirmed in public reporting either, which is not the same as ruling them out [13].
Watch for Apple and NCSC-NL, whose advisory is tracked as NCSC-2026-0280, to publish concrete IOCs and a persistence description [20][15]. Watch also for reports of one source IP hitting many Macs, which would distinguish opportunistic scanning from a campaign working a target list [16]. A miner is the cheapest possible use of root on a build machine; the access level on offer supports considerably more [4][6].