UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

macOS Screen Sharing Vulnerability Exploited in 2026

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

An authentication bypass in macOS Screen Sharing is being actively exploited to gain root access and install cryptomining malware, the Dutch NCSC has confirmed. For UK organisations with mixed-OS estates, this is a live patch-priority test of vulnerability management strategies and remote-access hygiene.

Patch status across macOS release lines
Tahoe 26Sequoia 15Sonoma 14Patched version26.6.115.7.914.8.9CVE-2026-65400 fixedYesYesYesJuly legacy VNC fix neededYes (26.6)N/AYes (14.8.8)Action if unpatchedUpdate nowUpdate nowUpdate now
View the data behind this chart
Patch status across macOS release lines
Tahoe 26Sequoia 15Sonoma 14
Patched version26.6.115.7.914.8.9
CVE-2026-65400 fixedYesYesYes
July legacy VNC fix neededYes (26.6)N/AYes (14.8.8)
Action if unpatchedUpdate nowUpdate nowUpdate now

What the NCSC is warning about

The Netherlands' National Cyber Security Centre has confirmed that a macOS authentication bypass flaw, tracked as CVE-2026-65400, is being exploited in the wild after public exploit code appeared. The vulnerability sits in macOS Screen Sharing, Apple's built-in remote desktop feature that runs over the VNC protocol on TCP port 5900.

According to the NCSC's updated advisory, it received a report of active abuse against multiple systems where port 5900 was reachable from the internet. In every case reported so far, the attacker obtained root access on the affected Mac and deployed a Monero cryptocurrency miner. The agency has not disclosed when the attacks began, how many systems are affected, or whether activity extends beyond cryptomining.

Inside the flaw and Apple's fix

The bug allows a network-based attacker to bypass credential checks entirely, meaning no valid username or password is required to reach a Mac over Screen Sharing. Once inside, an attacker can open applications, browse files, alter security settings, and — as seen in these attacks — escalate to root.

Apple patched CVE-2026-65400 on 6 August in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. The fix improves state management so credential validation is enforced correctly and rogue authentication attempts are rejected. Where an immediate update isn't possible, Apple's own guidance is to disable Screen Sharing via General → Sharing → Screen Sharing in System Settings.

Why mixed-OS estates are exposed

Most UK organisations no longer run single-vendor fleets. Macs sit alongside Windows laptops, Linux servers and cloud workloads, often supported by the same helpdesk and the same remote-access tooling. An authentication bypass on any endpoint in that chain undermines confidence in the whole estate, not just the affected devices.

This is the second Screen Sharing-related fix in recent months. Apple also patched CVE-2026-43760 on 27 July in macOS Tahoe 26.6 and macOS Sonoma 14.8.8, affecting systems with Screen Sharing or Remote Management enabled alongside the legacy 'VNC viewers may control screen with password' option. Teams that applied that July fix should not assume it covers this separate, more recent bypass — both patches need to be present, and both point to the same underlying risk: legacy remote-access options left switched on by default. Buyers relying on remote support should review their approach to securing macOS endpoints rather than treating Apple hardware as a lower priority than Windows.

Illustration: macOS Screen Sharing Vulnerability Exploited in 2026

A familiar attacker playbook

Turning an authentication bypass into a cryptominer deployment is not a novel technique. The same pattern has recently played out against the Qinglong task scheduler, exploited via chained flaws to modify configuration and pull down a miner, and against N-able N-central, where an auth bypass hit both hosted and on-premises servers simultaneously. SimpleHelp has seen comparable cryptomining activity following disclosure of a critical flaw.

The common thread is that remote-management and remote-support software is treated by attackers as the fastest route from exposed network to root access, because a single successful bypass often grants broad control. macOS has also seen a rise in ClickFix-delivered infostealers targeting cryptocurrency wallets, browser passwords and Apple Keychain data, and a 2021 macOS zero-day was previously weaponised by Shlayer malware — evidence that Apple endpoints are a routine target for financially motivated operators, not an afterthought.

What this means for third-party maintenance SLAs

For organisations that outsource Mac support, or run mixed-OS estates under a managed service contract, this incident is a useful stress test of existing agreements. Ask whether your third-party maintenance solutions provider has an explicit commitment to emergency patch deployment timelines, not just routine monthly cycles, and whether remote-access hardening is covered as a discrete deliverable.

Contracts should specify who is responsible for auditing which ports and remote-access services are internet-facing, and how quickly an out-of-band change can be approved when a vendor issues an emergency fix. Understanding IT maintenance SLAs in this context means checking that 'patch management' language actually covers auth-bypass severity incidents with defined turnaround, not vague best-effort clauses.

Attack chain seen by the NCSC
4Port 5900 exposed to internetScreen Sharing reachable externally3Authentication bypass exploitedCVE-2026-65400, no valid credentials needed2Root access obtainedFull control of the affected Mac1Monero miner deployedCryptomining payload installed
View the data behind this chart
Attack chain seen by the NCSC
LayerDetail
Port 5900 exposed to internetScreen Sharing reachable externally
Authentication bypass exploitedCVE-2026-65400, no valid credentials needed
Root access obtainedFull control of the affected Mac
Monero miner deployedCryptomining payload installed

Immediate steps for UK IT teams

The priority action is straightforward: update every managed Mac to macOS Tahoe 26.6.1, Sequoia 15.7.9 or Sonoma 14.8.9, and confirm the update has actually landed on remote and field devices, not just office-based endpoints. Where updates cannot be pushed immediately, disable Screen Sharing entirely rather than relying on network segmentation alone, since the flaw is an authentication bypass, not a network-layer weakness.

Audit firewall rules and any cloud security groups for TCP port 5900 exposed to the internet; this is the exact condition the NCSC says attackers are exploiting. Teams building out effective patch management processes should treat auth-bypass CVEs on remote-access features as top-tier priority regardless of platform, and confirm the fix covers both this bypass and the earlier legacy VNC issue from July.

Share
Key takeaways
  • CVE-2026-65400 is a macOS Screen Sharing authentication bypass, patched 6 August in Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.
  • The Dutch NCSC confirms active exploitation: attackers gain root access on exposed systems and deploy a Monero miner.
  • Exposure requires TCP port 5900 reachable from the internet — audit firewall and cloud security group rules now.
  • Mixed-OS estates should treat this as equal priority to Windows patching, and review third-party maintenance SLAs for emergency patch turnaround.
Frequently asked

FAQs — macOS Screen Sharing Vulnerability Exploited in 2026

What is CVE-2026-65400?

It's an authentication bypass in macOS Screen Sharing that lets a network-based attacker access a Mac without valid credentials. Apple fixed it on 6 August 2026 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.

How are attackers exploiting it right now?

The Dutch NCSC reports that on systems with TCP port 5900 exposed to the internet, attackers have obtained root access and installed a Monero cryptocurrency miner. Public exploit code for the flaw has already emerged.

How can we mitigate this if we can't patch immediately?

Apple's guidance is to disable Screen Sharing via System Settings (General → Sharing → Screen Sharing) until the update can be applied, and to ensure port 5900 is not reachable from the internet.

Is this the same issue as the July Screen Sharing fix?

No. Apple patched a separate legacy VNC-related issue, CVE-2026-43760, on 27 July in macOS Tahoe 26.6 and Sonoma 14.8.8. Both fixes should be applied, as they address different weaknesses in the same feature.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111