Apple patches Screen Sharing authentication-bypass flaw CVE-2026-65400 in macOS

Apple released macOS security updates to fix a flaw that could let someone on the same network get into Screen Sharing without valid credentials. The bug, CVE-2026-65400, has a CVSS severity score of 7.5 and was patched in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9; Apple says the issue allowed network-based authentication bypass of Screen Sharing.
Why it matters: People and organizations using Mac remote-access features should update quickly, especially on shared or enterprise networks, because an attacker nearby on the network could bypass login checks. Install the latest macOS updates on affected systems and limit Screen Sharing exposure where possible.

Sources

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
info@thehackernews.com (The Hacker News) 2026.08.19 42% relevant
If the article is referring to the recently patched macOS Screen Sharing issue now being exploited, it would be a follow-on update to Apple's macOS flaw story; however, the exact CVE is not confirmed from the provided text.
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
Ionut Arghire 2026.08.19 93% relevant
This source advances the story from patch release to active-response status by saying CISA added CVE-2026-65400 to KEV after in-the-wild abuse for root access and Monero mining.
Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Ionut Arghire 2026.08.17 97% relevant
This article updates that same Apple Screen Sharing flaw with post-patch developments: Dutch NCSC says CVE-2026-65400 is now being actively exploited on internet-exposed port 5900 systems, attackers are gaining root access and deploying Monero miners, and public exploit code is contributing to abuse.
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
info@thehackernews.com (The Hacker News) 2026.08.15 97% relevant
This article appears to update the same underlying event by adding exploitation details: the macOS Screen Sharing flaw CVE-2026-65400 is reportedly being abused on internet-exposed Macs to install a Monero miner, moving the story from patch availability to in-the-wild abuse.
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
Bill Toulas 2026.08.14 97% relevant
This article updates the same underlying event by adding that CVE-2026-65400 is now being actively exploited in the wild, with the Dutch NCSC reporting internet-exposed port 5900 systems were accessed, root was obtained, and Monero miners were deployed.
Microsoft, Apple Release Fresh Security Updates
Ionut Arghire 2026.08.07 100% relevant
This article establishes a separate Apple patch story centered on CVE-2026-65400, a specific newly fixed Screen Sharing authentication-bypass flaw not already represented in the tracked stories.
← Back to all stories