Published Monday, August 17, 2026 at 10:29 AM PT

BLUF: Apple’s recently patched macOS Screen Sharing vulnerability (CVE-2026-65400) is under active exploitation. Attackers bypass authentication, gain root access, and deploy Monero cryptominers on unpatched internet-facing Macs. Immediate action: patch macOS, isolate or disable Screen Sharing on exposed systems.
DETAILS
• Vulnerability: CVE-2026-65400 in macOS Screen Sharing permits unauthenticated remote access and root privilege escalation (confirmed by Netherlands NCSC, Help Net Security, BleepingComputer, The Hacker News, SecurityWeek, SecurityAffairs).
• Active exploitation: Threat actors are actively targeting and compromising vulnerable systems; confirmed payloads include Monero miners deployed post-compromise.
• Attack vector: Internet-exposed Macs running unpatched macOS are primary targets; authentication bypass allows direct access without credentials.
• Payload: Monero (XMR) cryptomining malware installed with root privileges, enabling persistent resource hijacking.
• Patch status: Apple has released a patch; systems running patched macOS are not affected. Unpatched systems remain vulnerable.
IMPACT
• Scope: All macOS systems with Screen Sharing enabled and accessible over the network, particularly internet-facing machines (servers, development systems, remote work devices).
• Severity: Root-level compromise on affected machines. Attackers can install persistent malware, establish backdoors, and conduct lateral movement within networks.
• Resource loss: Compromised systems used for unauthorized cryptocurrency mining, degrading performance and increasing electricity costs.
• Detection gap: Cryptominer activity may go unnoticed if not explicitly monitored; standard process monitoring alone may miss the deployed malware.
RECOMMENDED ACTIONS
Immediate: Patch all macOS systems to the latest available version containing CVE-2026-65400 fixes.
Urgent (if patching delayed): Disable Screen Sharing on internet-facing or untrusted networks; restrict Screen Sharing access via firewall rules to trusted IPs only.
Investigation: Check unpatched systems for unexpected processes consuming CPU (Monero miner signatures), unusual network connections, or persistence mechanisms (launchd agents, cron jobs).
Monitoring: Enable process and network logging to detect cryptomining activity (high CPU sustained, outbound connections to mining pools).
Network segmentation: Isolate any affected systems pending forensics; assume full root compromise until verified clean.
SOURCES
Netherlands National Cyber Security Centre (NCSC), Help Net Security, BleepingComputer, The Hacker News, SecurityWeek, SecurityAffairs, News4Hackers.
Recent high-severity events at publish time:

