Vulnerability giving attackers full control of Macs is under active exploitation
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A high-severity macOS vulnerability, CVE-2026-65400, in the screen sharing feature is being actively exploited to gain root access without credentials. Dutch cybersecurity officials (NCSC) reported active abuse on systems with port 5900 exposed to the internet, with attackers deploying Monero crypto miners after gaining root. Apple patched the flaw last week for macOS Tahoe, Sequoia, and Sonoma, rated 7.1/10 severity, stemming from a state management bug in screen sharing. Details became public at Black Hat security conference.
Questions this post answers
What is CVE-2026-65400 and how does it affect macOS screen sharing?
CVE-2026-65400 is a macOS vulnerability in the screen sharing feature that allows a remote attacker to gain root access without credentials, due to a flaw in state management tracking system events and variables. It carries a severity rating of 7.1 out of 10 and affects macOS Tahoe, Sequoia, and Sonoma. Apple patched it, and details were disclosed publicly at the Black Hat security conference. Mac admins tracking active exploits like this rely on daily.dev to stay ahead of patch cycles.
Is the macOS screen sharing vulnerability CVE-2026-65400 being actively exploited?
Yes, the Netherlands National Cyber Security Centrum confirmed active abuse on multiple systems where port 5900 was exposed to the internet. In every observed case, attackers gained root access and installed a Monero crypto miner on the compromised machine. Security teams monitoring active exploitation reports like this follow the space on daily.dev.
Which macOS versions received a patch for CVE-2026-65400?
Apple released patches for macOS Tahoe, Sequoia, and Sonoma to fix CVE-2026-65400, a screen sharing vulnerability that could let attackers execute malicious code and gain root access without a password. The patches shipped shortly before the flaw's public disclosure at Black Hat. Developers keeping macOS fleets patched track advisories like this through daily.dev.