# Critical macOS Screen Sharing flaw reported under active exploitation

_Saturday, August 15, 2026 at 3:24 AM EDT · Security · Developing · Tier 1 — Major_

![Critical macOS Screen Sharing flaw reported under active exploitation — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhudlXOxVGnImI0OoIDMwrIy0pc2zaf1aV0B4ga_QSrt5UPX5G_BJl76VvdEUxkxJ4pjopKLsohJrwVwBgS0a-xLJvW7ZvCPvG3ezz_5vY1ABYZnysPR-ZFvVlEXVdZkCWuuHp2IAra5N3IgH_Lf8wuwVF7hx4zYXf0qF7MyOC8M83ZpQVQ5jcjzbLP4Jq/s1700-e365/apple-screenshare.jpg)

The Netherlands National Cyber Security Centre has reported active abuse of CVE-2026-65400, a critical macOS Screen Sharing authentication flaw, on multiple systems with internet-accessible port 5900.

The agency said attackers gained root access and installed Monero miners in the reported cases. Apple addressed the issue in emergency updates for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. The flaw affects Screen Sharing and could let an attacker already on a network authenticate to the built-in remote-desktop service without valid credentials.

Apple said its fix improves state management to enforce credential validation.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html)

---
Canonical: https://techandbusiness.org/newswire/b8hyFmFkj3D6jqBl2Mgc_w
Retrieved: 2026-08-18T09:33:20.181Z
Publisher: Tech & Business (techandbusiness.org)
