# macOS Screen Sharing vulnerability exploitation

> Live situation record from CLSTR: https://clstr.news/situations/macos-screen-sharing-vulnerability-exploitation
> Updated: 2026-08-19T01:12:00.000Z. Sources: 37. Developments: 2.

A critical authentication vulnerability in macOS Screen Sharing, identified as CVE-2026-65400, is being actively exploited by threat actors to gain remote root access to affected systems. The flaw allows attackers to bypass password requirements due to errors in how the system manages login states, particularly when port 5900 is exposed to the internet.

Security agencies and firms have noted that attackers are using this exploit for cryptojacking, specifically installing Monero (XMR) cryptocurrency mining software on compromised machines. The Dutch National Cyber Security Centre (NCSC) has confirmed real-world exploitation, and security firm Huntress reported finding tens of thousands of potentially vulnerable hosts.

In response to the threat, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) upgraded the vulnerability’s severity score from 7.1 to a critical 9.8, noting that the exploit can be fully automated and requires no prior privileges. The vulnerability specifically involves the Screen Sharing service’s implementation of the Secure Remote Password (SRP) protocol. If System Integrity Protection (SIP) is disabled, attackers can execute arbitrary code with elevated privileges. Security researcher Alfredo Pesoli, CEO of Bynario, is credited with identifying the flaw through automated detection systems.

Apple released emergency security updates on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to address the issue. Users are urged to update their software immediately to mitigate the risk of cryptocurrency mining Trojans being installed via this flaw.

## Claims

- The vulnerability is officially registered as CVE-2026-65400. (corroborated by 4 sources)
- The flaw allows remote attackers to access a Mac without a password or user interaction via the Screen Sharing service. (corroborated by 4 sources)
- The National Cyber Security Centre of the Netherlands (NCSC-NL) reported real-world attacks exploiting the flaw. (corroborated by 3 sources)
- The vulnerability affects macOS Sequoia, Sonoma, and Tahoe versions. (corroborated by 3 sources)
- Attackers have used the exploit to install cryptocurrency mining Trojans. (corroborated by 3 sources)
- Alfredo Pesoli, CEO of Bynario, identified the flaw using automated detection systems. (single source)
- The vulnerability was assigned a severity score of 9.8 out of 10. (single source)

## Timeline

### 2026-08-19: Apple patches critical macOS Screen Sharing vulnerability

Apple released emergency patches for a critical macOS Screen Sharing vulnerability (CVE-2026-65400) being actively exploited by attackers to install cryptocurrency miners and gain root access.

6 sources. https://clstr.news/cluster/macos-screen-sharing-vulnerability-allows-remote-root-access

### 2026-08-16: macOS Screen Sharing vulnerability exploited for Monero mining

Attackers are exploiting a critical macOS Screen Sharing vulnerability (CVE-2026-65400) to gain root access and install Monero miners. CISA has rated the flaw as a critical 9.8 severity.

32 sources. https://clstr.news/cluster/macos-screen-sharing-vulnerability-exploited-for-monero-mining

---
Cite as: macOS Screen Sharing vulnerability exploitation. CLSTR, https://clstr.news/situations/macos-screen-sharing-vulnerability-exploitation
