# Active macOS Screen Sharing exploits give attackers root access

_Published Sunday, August 16, 2026 at 12:58 PM EDT · Security · Breaking · Tier 1 — Major_

![macOS 26 Tahoe — Primary](https://cdn.mos.cms.futurecdn.net/oP4PrsunH4mjQz37TZeD23-2560-80.jpg)

Attackers are actively exploiting CVE-2026-65400, an authentication-bypass flaw in macOS Screen Sharing, to compromise internet-exposed Macs, according to the Dutch National Cyber Security Centre.

The agency said reported incidents involved root access and installation of Monero miners. Apple issued an out-of-band patch on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. CISA subsequently raised the vulnerability's CVSS score from 7.1 to 9.8 and assessed the attack as automatable.

Screen Sharing is disabled by default, but systems with TCP port 5900 exposed are at risk.

## Sources

- [Tom's Hardware](https://www.tomshardware.com/tech-industry/cyber-security/macos-screen-sharing-flaw-exploited-to-root-macs-and-plant-monero-miners)

---
Canonical: https://techandbusiness.org/newswire/tCiHDzkx02jlWT_vy2qUn-
Published: 2026-08-16T16:58:13.333Z
Story chronology: 2026-08-16T13:00:00.000Z
Retrieved: 2026-09-30T21:30:11.766Z
Publisher: Tech & Business (techandbusiness.org)
