< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 37 sources · 3 days · First seen · Last updated

macOS Screen Sharing vulnerability exploitation

Overview

A critical authentication vulnerability in macOS Screen Sharing, identified as CVE-2026-65400, is being actively exploited by threat actors to gain remote root access to affected systems. The flaw allows attackers to bypass password requirements due to errors in how the system manages login states, particularly when port 5900 is exposed to the internet.

Security agencies and firms have noted that attackers are using this exploit for cryptojacking, specifically installing Monero (XMR) cryptocurrency mining software on compromised machines. The Dutch National Cyber Security Centre (NCSC) has confirmed real-world exploitation, and security firm Huntress reported finding tens of thousands of potentially vulnerable hosts.

In response to the threat, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) upgraded the vulnerability’s severity score from 7.1 to a critical 9.8, noting that the exploit can be fully automated and requires no prior privileges. The vulnerability specifically involves the Screen Sharing service’s implementation of the Secure Remote Password (SRP) protocol. If System Integrity Protection (SIP) is disabled, attackers can execute arbitrary code with elevated privileges. Security researcher Alfredo Pesoli, CEO of Bynario, is credited with identifying the flaw through automated detection systems.

Apple released emergency security updates on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to address the issue. Users are urged to update their software immediately to mitigate the risk of cryptocurrency mining Trojans being installed via this flaw.

Entities

CISA · NCSC-NL · Apple · macOS · Bynario

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 24 days ago

    [TECHNOLOGY] 6 sources
    Apple patches critical macOS Screen Sharing vulnerability

    Apple released emergency patches for a critical macOS Screen Sharing vulnerability (CVE-2026-65400) being actively exploited by attackers to install cryptocurrency miners and gain root access.

  2. 26 days ago

    [TECHNOLOGY] 32 sources
    macOS Screen Sharing vulnerability exploited for Monero mining

    Attackers are exploiting a critical macOS Screen Sharing vulnerability (CVE-2026-65400) to gain root access and install Monero miners. CISA has rated the flaw as a critical 9.8 severity.

Sources

9to5mac.com · apfelpage.de · bitcoinethereumnews.com · blogspan.net · btc-echo.de · cafef.vn · cybernoz.com · dday.it · directioninformatique.com · go4it.ro · gradschool.umn.edu · hothardware.com · iclarified.com · iosmac.es · isc.sans.edu · it-boltwise.de · itdaily.be · ithome.com · itnewsafrica.com · kansrijk.nl · macrumors.com · mactechnews.de · manybutfinite.com · me.mashable.com · mobzine.ro · mrmad.com.tw · news18.com · newsbit.nl · pisapapeles.net · que.com · skoob.com · soha.vn · thanhnien.vn · theregister.co.uk · therogueginger.com · webtekno.com · wwwhatsnew.com

This summary has been updated 2 times: see revision history