Urgent Security Update: Apple Patches Critical macOS Screen Sharing Vulnerability Exploited for Monero Mining
September 8, 2026
First, apply the Apple update and verify whether Screen Sharing is needed; if not, disable it and avoid relying on password changes as a fix since the flaw lies in the authentication path itself.
In real-world incidents, attackers have gained root access on affected Macs and installed Monero miners, underscoring plausible damage but not a guaranteed outcome for every system.
The vulnerability, CVE-2026-65400, is an authentication flaw in macOS Screen Sharing that can allow attackers to log in without valid credentials, effectively bypassing the login check.
Exploitation requires a vulnerable macOS version with network reach to Screen Sharing, with particular risk when port 5900 is exposed to the Internet; attacks have targeted internet-facing 5900.
Apple patched the flaw on August 6, 2026, in macOS Sonoma 14.8.9, macOS Sequoia 15.7.9, and macOS Tahoe 26.6.1; users on older builds should update immediately if Screen Sharing is reachable over the network.
The fixed ranges are: Sonoma 14.0–14.8.8 updated to 14.8.9; Sequoia 15.0–15.7.8 updated to 15.7.9; Tahoe 26.0–26.6.0 updated to 26.6.1; users should confirm their version and apply the appropriate update.
If an immediate update isn’t possible, temporarily disable Screen Sharing and block direct public access to TCP port 5900 to reduce exposure.
Summary based on 1 source
Get a daily email with more Tech stories
Source

NeoTeo • Sep 8, 2026
CVE-2026-65400: Update macOS Screen Sharing