Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 37 sources · 3 days · First seen · Last updated
macOS Screen Sharing vulnerability exploitation
Overview
A critical authentication vulnerability in macOS Screen Sharing, identified as CVE-2026-65400, is being actively exploited by threat actors to gain remote root access to affected systems. The flaw allows attackers to bypass password requirements due to errors in how the system manages login states, particularly when port 5900 is exposed to the internet.
Security agencies and firms have noted that attackers are using this exploit for cryptojacking, specifically installing Monero (XMR) cryptocurrency mining software on compromised machines. The Dutch National Cyber Security Centre (NCSC) has confirmed real-world exploitation, and security firm Huntress reported finding tens of thousands of potentially vulnerable hosts.
In response to the threat, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) upgraded the vulnerability’s severity score from 7.1 to a critical 9.8, noting that the exploit can be fully automated and requires no prior privileges. The vulnerability specifically involves the Screen Sharing service’s implementation of the Secure Remote Password (SRP) protocol. If System Integrity Protection (SIP) is disabled, attackers can execute arbitrary code with elevated privileges. Security researcher Alfredo Pesoli, CEO of Bynario, is credited with identifying the flaw through automated detection systems.
Apple released emergency security updates on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to address the issue. Users are urged to update their software immediately to mitigate the risk of cryptocurrency mining Trojans being installed via this flaw.
Entities
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 4 SOURCES] The vulnerability is officially registered as CVE-2026-65400. pisapapeles.net · wwwhatsnew.com · cybernoz.com · www.datasecuritybreach.fr
- [● 4 SOURCES] The flaw allows remote attackers to access a Mac without a password or user interaction via the Screen Sharing service. pisapapeles.net · wwwhatsnew.com · cybernoz.com · www.datasecuritybreach.fr
- [● 3 SOURCES] The National Cyber Security Centre of the Netherlands (NCSC-NL) reported real-world attacks exploiting the flaw. pisapapeles.net · wwwhatsnew.com · www.datasecuritybreach.fr
- [● 3 SOURCES] The vulnerability affects macOS Sequoia, Sonoma, and Tahoe versions. pisapapeles.net · wwwhatsnew.com · www.datasecuritybreach.fr
- [● 3 SOURCES] Attackers have used the exploit to install cryptocurrency mining Trojans. pisapapeles.net · wwwhatsnew.com · www.datasecuritybreach.fr
- [○ 1 SOURCE] Alfredo Pesoli, CEO of Bynario, identified the flaw using automated detection systems. pisapapeles.net
- [○ 1 SOURCE] The vulnerability was assigned a severity score of 9.8 out of 10. pisapapeles.net
Timeline
-
24 days ago
[TECHNOLOGY] 6 sourcesApple patches critical macOS Screen Sharing vulnerabilityApple released emergency patches for a critical macOS Screen Sharing vulnerability (CVE-2026-65400) being actively exploited by attackers to install cryptocurrency miners and gain root access.
-
26 days ago
[TECHNOLOGY] 32 sourcesmacOS Screen Sharing vulnerability exploited for Monero miningAttackers are exploiting a critical macOS Screen Sharing vulnerability (CVE-2026-65400) to gain root access and install Monero miners. CISA has rated the flaw as a critical 9.8 severity.
Sources
9to5mac.com · apfelpage.de · bitcoinethereumnews.com · blogspan.net · btc-echo.de · cafef.vn · cybernoz.com · dday.it · directioninformatique.com · go4it.ro · gradschool.umn.edu · hothardware.com · iclarified.com · iosmac.es · isc.sans.edu · it-boltwise.de · itdaily.be · ithome.com · itnewsafrica.com · kansrijk.nl · macrumors.com · mactechnews.de · manybutfinite.com · me.mashable.com · mobzine.ro · mrmad.com.tw · news18.com · newsbit.nl · pisapapeles.net · que.com · skoob.com · soha.vn · thanhnien.vn · theregister.co.uk · therogueginger.com · webtekno.com · wwwhatsnew.com
This summary has been updated 2 times: see revision history