Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-15 ยท updated: 2026-08-15 ยท tags: [cve, apple, macos, rce, screen-sharing, active-exploitation, crypto-mining, sector-global-macro] ยท confidence: high ยท severity: high ยท affected_sectors: [global-macro] ยท au_impact: false

CVE-2026-65400 โ€” macOS Screen Sharing RCE Under Active Exploitation

CVE-2026-65400 is a vulnerability in Apple macOS Screen Sharing state management that is under active exploitation. Rated CVSS 7.1, it lets an unauthenticated remote attacker log in to a target Mac without a password, view the screen, and control the keyboard and mouse.

Summary

The flaw exists in how macOS handles the Screen Sharing state machine, allowing authentication to be bypassed on systems that expose the Screen Sharing service. The Netherlands' National Cyber Security Centre (NCSC) warned of active exploitation targeting systems with port 5900 exposed to the internet. In observed attacks, threat actors obtained root access and installed a Monero cryptocurrency miner. Apple released patches within the last week covering macOS Tahoe, Sequoia and Sonoma.

Key Facts

Field Value
CVE CVE-2026-65400
CVSS 7.1 (High)
Type Authentication bypass leading to remote code execution / full control
Component macOS Screen Sharing
Pre-condition Screen Sharing service (port 5900) exposed
Impact Unauthenticated remote login, screen view, keyboard/mouse control, root access
Observed Root access obtained; Monero crypto-miner installed
Status Under active exploitation; patched by Apple

Sector

Global (Macro) โ€” Internet-exposed macOS Screen Sharing services present a broad, cross-sector attack surface relevant to individuals, enterprises, government and healthcare alike.

Source

https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/

Reliability

Tier 2 โ€” Established cyber journalism (Ars Technica), reporting on an official Netherlands NCSC warning; incident status confirmed.

Date

2026-08-15

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-15