What happened
A recently patched authentication flaw in macOS Screen Sharing, tracked as CVE-2026-65400, is being actively exploited. The Netherlands' National Cyber Security Centre reported attackers compromising Macs whose Screen Sharing service, port 5900, is exposed to the internet; in the cases reported to the agency, attackers gained root access and installed the XMRig 6.26.0 Monero cryptocurrency miner. Microsoft separately observed exploitation on a limited number of macOS devices, with telemetry showing successful root sign-ins through Screen Sharing. The flaw lets a network-based attacker authenticate to the remote desktop service without valid credentials. Apple patched it on August 6 in updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, and on August 14 CISA raised the vulnerability's severity score from 7.1 to 9.8 after the reports of active exploitation. Public proof-of-concept code is circulating.
Why it matters for your business
Plenty of small offices have a Mac that doubles as a file server or a machine the owner reaches from home with Screen Sharing turned on. That convenience is exactly the exposure being exploited here. A crypto miner is the visible symptom, slowing the machine and running up power use, but the real problem is that the attacker holds root: everything on that Mac, and anything it connects to, is within reach. Mac-based shops often skip the patching discipline that Windows environments learned the hard way.
What to do about it
- Update every Mac now; fixes shipped for the last three macOS versions on August 6.
- Turn off Screen Sharing and Remote Management on machines that do not need it, in System Settings under Sharing.
- Never expose port 5900 to the internet; reach office machines through a VPN or a zero-trust remote access tool instead.
- On any Mac that had Screen Sharing internet-exposed, check for unfamiliar login items, LaunchDaemons, and SSH keys, and watch for constant high CPU use.
