CVE-2026-65400 Exploited via macOS Screen Sharing

Brendan Smith
Brendan Smith - Cybersecurity Analyst
7 Min Read
Port 5900 opens like a door as root access spreads through macOS Screen Sharing.
Internet-exposed Screen Sharing can turn port 5900 into a path to root access on an unpatched Mac.

The Netherlands’ National Cyber Security Centre says attackers are actively exploiting CVE-2026-65400 against Macs that have Screen Sharing enabled and TCP port 5900 reachable from the internet. In observed attacks, the intruders obtained root privileges and installed cryptomining software.

This does not mean every Mac is remotely exposed. The observed attack path required Screen Sharing to be on and reachable from outside the trusted network. Apple released fixes on August 6, 2026, but updating a Mac that was already compromised does not remove an installed miner, a new account, or root-level persistence.

Which macOS versions fix CVE-2026-65400?

macOS branch Fixed version
macOS Tahoe 26 26.6.1
macOS Sequoia 15 15.7.9
macOS Sonoma 14 14.8.9

Apple describes CVE-2026-65400 as an authentication issue in Screen Sharing that was fixed through improved state management. A network attacker could authenticate to the service without valid credentials. Install the update offered for the maintained macOS branch rather than trying to move between major releases solely to match another row.

Is your Mac exposed through Screen Sharing?

A vulnerable version alone shows that the flaw is present, not that the observed internet attack path is open. Check both the Mac and the network edge:

  1. Open Apple menu → System Settings → General → Sharing.
  2. If Screen Sharing is on and you do not need it, turn it off. Also check whether Remote Management is enabled in a managed environment.
  3. Review the router, firewall, cloud security group, VPN gateway, and remote-access appliance for any rule that forwards or exposes TCP port 5900 to the Mac.
  4. Remove direct public exposure. If remote administration is required, restrict it to a trusted VPN or other authenticated access layer and limit the allowed users.
  5. Open System Settings → General → Software Update, install the current security update, restart, and verify the resulting macOS version.

Do not rely on a public “port checker” alone for a work Mac: the result can be affected by NAT, a gateway, temporary firewall rules, or a service listening only on another interface. Administrators should verify the rule at the network boundary and check the host configuration directly.

Exposure and compromise are different decisions

What you find What to do
Screen Sharing was off and no 5900 rule exists Install the security update normally and keep the service disabled unless it is needed.
Screen Sharing was on, but limited to a trusted local network or protected remote-access layer Update promptly, review allowed users and access logs, and confirm there was no unintended internet route.
TCP 5900 was reachable from the internet Remove exposure, update, review logs and accounts, and treat the period of exposure as an incident that needs scoping.
The Mac shows suspicious activity after exposure Isolate it and investigate for compromise; do not assume the patch cleaned the system.

Signs that need incident response

The Dutch NCSC has not published a file hash, process name, or persistence path that uniquely identifies the observed miner. High CPU usage by itself is not proof of CVE-2026-65400 exploitation. It becomes more concerning when it follows public Screen Sharing exposure and appears with one or more of these changes:

  • persistent high CPU, fan activity, or energy use while the Mac is idle;
  • an unfamiliar mining process, downloaded binary, LaunchAgent, LaunchDaemon, login item, or scheduled task;
  • a new local administrator, changed sharing permission, or unfamiliar remote session;
  • security alerts, unexplained outbound connections, or processes that return after termination;
  • unexpected changes to accounts, browser sessions, SSH keys, or remote-management tools.

A root-level intrusion can alter logs and security settings, so the absence of one visible miner process is not a clean bill of health. This is also a different intrusion path from AmnesiaStealer delivered through a copied Terminal command: both can require containment, but only one starts with ClickFix-style user execution.

What to do if compromise is plausible

  1. Disconnect the Mac from untrusted networks. For an organization, contact the security or IT team before wiping evidence.
  2. Preserve useful evidence. Record the time window, public IP and firewall rules, Screen Sharing settings, remote-access logs, local users, running processes, persistence items, and security alerts.
  3. Remove the public route and install Apple’s update. The patch closes the authentication flaw but is not a malware-removal action.
  4. Review for persistence and unauthorized access. Check local administrators, Login Items, LaunchAgents, LaunchDaemons, configuration profiles, scheduled tasks, SSH access, and remote-management software.
  5. Rotate sensitive credentials from a known-clean device after containment. Revoke important sessions and review the Apple Account, email, password manager, financial accounts, and developer credentials used on the Mac.
  6. Rebuild when trust cannot be restored. If root compromise is confirmed or cannot be scoped reliably, a clean macOS reinstall and selective restoration of known-good data may be safer than deleting one miner process.

Keep backups and evidence separate from the affected Mac. If credentials or live browser sessions may have been exposed, use the account recovery checklist to prioritize revocation and password changes.

References

  1. National Cyber Security Centre of the Netherlands. “Vulnerability in macOS Screen Sharing,” published August 7 and updated August 13, 2026. Active-exploitation alert and exposure conditions.
  2. Apple. “About the security content of macOS Tahoe 26.6.1,” released August 6, 2026. Tahoe security advisory.
  3. Apple. “About the security content of macOS Sequoia 15.7.9,” released August 6, 2026. Sequoia security advisory.
  4. Apple. “About the security content of macOS Sonoma 14.8.9,” released August 6, 2026. Sonoma security advisory.
  5. Apple Support. “Turn Mac screen sharing on or off,” accessed August 18, 2026. Official Screen Sharing settings.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?