Apple released security updates for macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9 to fix CVE-2026-65400, an authentication flaw in Screen Sharing that could let an attacker on the network log in without valid credentials. Apple said the bug was caused by an authentication issue and was remediated through improved state management; the company also issued a corresponding fix for macOS Tahoe 26.6.1. The vulnerability was reported by Alfredo Pesoli (@__rev) via Bynario Atlas.
The flaw is now being actively exploited after public exploit code became available. According to reporting citing the Netherlands’ National Cyber Security Centre, attackers have targeted systems with VNC port 5900 exposed to the internet, gained root access, and deployed a Monero cryptocurrency miner. Organizations running affected macOS systems have been urged to apply Apple’s updates immediately or disable Screen Sharing until patching is complete.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On August 18, CISA added CVE-2026-65400 to its Known Exploited Vulnerabilities catalog. The listing reflects that the macOS Screen Sharing authentication bypass is being actively exploited in the wild.
On August 14, CISA replaced the original CVSS vector for CVE-2026-65400 and increased its score from 7.1 to 9.8. The revised assessment said the flaw requires no privileges and can enable full compromise of confidentiality, integrity, and availability.
On August 7, the Netherlands' National Cyber Security Centre published its first advisory on CVE-2026-65400, one day after Apple's patch. The advisory was initially informational because no exploitation had been reported at that time.
In Apple's security content for the affected macOS releases, the company publicly credited Bynario Atlas in connection with CVE-2026-65400. The disclosure accompanied Apple's description of the flaw as a pre-authentication Screen Sharing issue that could enable root-level code execution.
On August 6, Apple fixed the Screen Sharing authentication bypass tracked as CVE-2026-65400. The patch was released in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9, with Apple describing the issue as an authentication flaw addressed through improved state management.
According to the Dutch NCSC, attackers exploiting CVE-2026-65400 obtained root access on affected macOS systems and installed a Monero cryptocurrency miner. Active abuse was observed on multiple systems with internet-accessible port 5900.
The Netherlands' National Cyber Security Centre said it received reports that CVE-2026-65400 was being exploited in the wild. The reported attacks targeted systems with internet-exposed VNC port 5900.
The Netherlands' National Cyber Security Centre said public exploit code became available for CVE-2026-65400. The source content does not anchor a specific date for when the exploit code was released.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
21 references tracked. Mallory keeps watching after this page renders.
runzero.com
Open sourceheise.de
Open sourcexakep.ru
Open sourcecyber.gc.ca
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourcecve.org
Open sourcebugflation.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.