# Active macOS Screen Sharing exploits give attackers root access

_Sunday, August 16, 2026 at 9:00 AM EDT · Security · Breaking · Tier 1 — Major_

![Active macOS Screen Sharing exploits give attackers root access — Primary](https://cdn.mos.cms.futurecdn.net/oP4PrsunH4mjQz37TZeD23-2560-80.jpg)

Attackers are actively exploiting CVE-2026-65400, an authentication-bypass flaw in macOS Screen Sharing, to compromise internet-exposed Macs, according to the Dutch National Cyber Security Centre.

The agency said reported incidents involved root access and installation of Monero miners. Apple issued an out-of-band patch on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. CISA subsequently raised the vulnerability's CVSS score from 7.1 to 9.8 and assessed the attack as automatable.

Screen Sharing is disabled by default, but systems with TCP port 5900 exposed are at risk.

## Sources

- [Latest from Tom's Hardware](https://www.tomshardware.com/tech-industry/cyber-security/macos-screen-sharing-flaw-exploited-to-root-macs-and-plant-monero-miners)

---
Canonical: https://techandbusiness.org/newswire/tCiHDzkx02jlWT_vy2qUn-
Retrieved: 2026-08-16T19:18:39.822Z
Publisher: Tech & Business (techandbusiness.org)
