Published Monday, August 17, 2026 at 10:29 AM PT

<strong>macOS Screen Sharing Authentication Bypass (CVE-2026-65400) — Active Exploitation for Cryptomining</strong>


BLUF: Apple’s recently patched macOS Screen Sharing vulnerability (CVE-2026-65400) is under active exploitation. Attackers bypass authentication, gain root access, and deploy Monero cryptominers on unpatched internet-facing Macs. Immediate action: patch macOS, isolate or disable Screen Sharing on exposed systems.


DETAILS

Vulnerability: CVE-2026-65400 in macOS Screen Sharing permits unauthenticated remote access and root privilege escalation (confirmed by Netherlands NCSC, Help Net Security, BleepingComputer, The Hacker News, SecurityWeek, SecurityAffairs).

Active exploitation: Threat actors are actively targeting and compromising vulnerable systems; confirmed payloads include Monero miners deployed post-compromise.

Attack vector: Internet-exposed Macs running unpatched macOS are primary targets; authentication bypass allows direct access without credentials.

Payload: Monero (XMR) cryptomining malware installed with root privileges, enabling persistent resource hijacking.

Patch status: Apple has released a patch; systems running patched macOS are not affected. Unpatched systems remain vulnerable.


IMPACT

Scope: All macOS systems with Screen Sharing enabled and accessible over the network, particularly internet-facing machines (servers, development systems, remote work devices).

Severity: Root-level compromise on affected machines. Attackers can install persistent malware, establish backdoors, and conduct lateral movement within networks.

Resource loss: Compromised systems used for unauthorized cryptocurrency mining, degrading performance and increasing electricity costs.

Detection gap: Cryptominer activity may go unnoticed if not explicitly monitored; standard process monitoring alone may miss the deployed malware.


RECOMMENDED ACTIONS

  1. Immediate: Patch all macOS systems to the latest available version containing CVE-2026-65400 fixes.

  2. Urgent (if patching delayed): Disable Screen Sharing on internet-facing or untrusted networks; restrict Screen Sharing access via firewall rules to trusted IPs only.

  3. Investigation: Check unpatched systems for unexpected processes consuming CPU (Monero miner signatures), unusual network connections, or persistence mechanisms (launchd agents, cron jobs).

  4. Monitoring: Enable process and network logging to detect cryptomining activity (high CPU sustained, outbound connections to mining pools).

  5. Network segmentation: Isolate any affected systems pending forensics; assume full root compromise until verified clean.


SOURCES

Netherlands National Cyber Security Centre (NCSC), Help Net Security, BleepingComputer, The Hacker News, SecurityWeek, SecurityAffairs, News4Hackers.


Recent high-severity events at publish time:

Recent high-severity events