An authentication bypass in macOS Screen Sharing is being actively exploited to gain root access and install cryptomining malware, the Dutch NCSC has confirmed. For UK organisations with mixed-OS estates, this is a live patch-priority test of vulnerability management strategies and remote-access hygiene.
View the data behind this chart
| Tahoe 26 | Sequoia 15 | Sonoma 14 | |
|---|---|---|---|
| Patched version | 26.6.1 | 15.7.9 | 14.8.9 |
| CVE-2026-65400 fixed | Yes | Yes | Yes |
| July legacy VNC fix needed | Yes (26.6) | N/A | Yes (14.8.8) |
| Action if unpatched | Update now | Update now | Update now |
What the NCSC is warning about
The Netherlands' National Cyber Security Centre has confirmed that a macOS authentication bypass flaw, tracked as CVE-2026-65400, is being exploited in the wild after public exploit code appeared. The vulnerability sits in macOS Screen Sharing, Apple's built-in remote desktop feature that runs over the VNC protocol on TCP port 5900.
According to the NCSC's updated advisory, it received a report of active abuse against multiple systems where port 5900 was reachable from the internet. In every case reported so far, the attacker obtained root access on the affected Mac and deployed a Monero cryptocurrency miner. The agency has not disclosed when the attacks began, how many systems are affected, or whether activity extends beyond cryptomining.
Inside the flaw and Apple's fix
The bug allows a network-based attacker to bypass credential checks entirely, meaning no valid username or password is required to reach a Mac over Screen Sharing. Once inside, an attacker can open applications, browse files, alter security settings, and — as seen in these attacks — escalate to root.
Apple patched CVE-2026-65400 on 6 August in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. The fix improves state management so credential validation is enforced correctly and rogue authentication attempts are rejected. Where an immediate update isn't possible, Apple's own guidance is to disable Screen Sharing via General → Sharing → Screen Sharing in System Settings.
Why mixed-OS estates are exposed
Most UK organisations no longer run single-vendor fleets. Macs sit alongside Windows laptops, Linux servers and cloud workloads, often supported by the same helpdesk and the same remote-access tooling. An authentication bypass on any endpoint in that chain undermines confidence in the whole estate, not just the affected devices.
This is the second Screen Sharing-related fix in recent months. Apple also patched CVE-2026-43760 on 27 July in macOS Tahoe 26.6 and macOS Sonoma 14.8.8, affecting systems with Screen Sharing or Remote Management enabled alongside the legacy 'VNC viewers may control screen with password' option. Teams that applied that July fix should not assume it covers this separate, more recent bypass — both patches need to be present, and both point to the same underlying risk: legacy remote-access options left switched on by default. Buyers relying on remote support should review their approach to securing macOS endpoints rather than treating Apple hardware as a lower priority than Windows.

A familiar attacker playbook
Turning an authentication bypass into a cryptominer deployment is not a novel technique. The same pattern has recently played out against the Qinglong task scheduler, exploited via chained flaws to modify configuration and pull down a miner, and against N-able N-central, where an auth bypass hit both hosted and on-premises servers simultaneously. SimpleHelp has seen comparable cryptomining activity following disclosure of a critical flaw.
The common thread is that remote-management and remote-support software is treated by attackers as the fastest route from exposed network to root access, because a single successful bypass often grants broad control. macOS has also seen a rise in ClickFix-delivered infostealers targeting cryptocurrency wallets, browser passwords and Apple Keychain data, and a 2021 macOS zero-day was previously weaponised by Shlayer malware — evidence that Apple endpoints are a routine target for financially motivated operators, not an afterthought.
What this means for third-party maintenance SLAs
For organisations that outsource Mac support, or run mixed-OS estates under a managed service contract, this incident is a useful stress test of existing agreements. Ask whether your third-party maintenance solutions provider has an explicit commitment to emergency patch deployment timelines, not just routine monthly cycles, and whether remote-access hardening is covered as a discrete deliverable.
Contracts should specify who is responsible for auditing which ports and remote-access services are internet-facing, and how quickly an out-of-band change can be approved when a vendor issues an emergency fix. Understanding IT maintenance SLAs in this context means checking that 'patch management' language actually covers auth-bypass severity incidents with defined turnaround, not vague best-effort clauses.
View the data behind this chart
| Layer | Detail |
|---|---|
| Port 5900 exposed to internet | Screen Sharing reachable externally |
| Authentication bypass exploited | CVE-2026-65400, no valid credentials needed |
| Root access obtained | Full control of the affected Mac |
| Monero miner deployed | Cryptomining payload installed |
Immediate steps for UK IT teams
The priority action is straightforward: update every managed Mac to macOS Tahoe 26.6.1, Sequoia 15.7.9 or Sonoma 14.8.9, and confirm the update has actually landed on remote and field devices, not just office-based endpoints. Where updates cannot be pushed immediately, disable Screen Sharing entirely rather than relying on network segmentation alone, since the flaw is an authentication bypass, not a network-layer weakness.
Audit firewall rules and any cloud security groups for TCP port 5900 exposed to the internet; this is the exact condition the NCSC says attackers are exploiting. Teams building out effective patch management processes should treat auth-bypass CVEs on remote-access features as top-tier priority regardless of platform, and confirm the fix covers both this bypass and the earlier legacy VNC issue from July.
- 01BleepingComputer — Hackers exploit macOS Screen Sharing flaw to deploy Monero miner · 14 August 2026
- 02BleepingComputer — Hackers exploit RCE flaws in Qinglong task scheduler for cryptomining · 1 August 2026
- 03BleepingComputer — Apple fixes macOS zero-day bug exploited by Shlayer malware · 17 May 2021
- 04BleepingComputer — ClickFix attack pushes macOS infostealer for crypto theft attacks · 20 July 2026
