CVE-2026-65400 โ macOS Screen Sharing RCE Under Active Exploitation
CVE-2026-65400 is a vulnerability in Apple macOS Screen Sharing state management that is under active exploitation. Rated CVSS 7.1, it lets an unauthenticated remote attacker log in to a target Mac without a password, view the screen, and control the keyboard and mouse.
Summary
The flaw exists in how macOS handles the Screen Sharing state machine, allowing authentication to be bypassed on systems that expose the Screen Sharing service. The Netherlands' National Cyber Security Centre (NCSC) warned of active exploitation targeting systems with port 5900 exposed to the internet. In observed attacks, threat actors obtained root access and installed a Monero cryptocurrency miner. Apple released patches within the last week covering macOS Tahoe, Sequoia and Sonoma.
Key Facts
| Field | Value |
|---|---|
| CVE | CVE-2026-65400 |
| CVSS | 7.1 (High) |
| Type | Authentication bypass leading to remote code execution / full control |
| Component | macOS Screen Sharing |
| Pre-condition | Screen Sharing service (port 5900) exposed |
| Impact | Unauthenticated remote login, screen view, keyboard/mouse control, root access |
| Observed | Root access obtained; Monero crypto-miner installed |
| Status | Under active exploitation; patched by Apple |
Sector
Global (Macro) โ Internet-exposed macOS Screen Sharing services present a broad, cross-sector attack surface relevant to individuals, enterprises, government and healthcare alike.
Source
https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/
Reliability
Tier 2 โ Established cyber journalism (Ars Technica), reporting on an official Netherlands NCSC warning; incident status confirmed.
Date
2026-08-15
Related Pages
- Vulnerability Giving Attackers Full Control Of Macs Is Under Active Exploitation โ Incident coverage of this active exploitation
Sources: raw/digests/Cyber-Digest-2026-08-15