Technology newsroom
Critical 9.8 macOS Screen Sharing Vulnerability Exploited for Monero Mining
A critical 9.8 vulnerability (CVE-2026-65400) in macOS Screen Sharing is actively being exploited by hackers to gain Root access and install Monero cryptocurrency miners. Apple has released patches, and users are urged to update immediately.
π Key Highlights:
- A critical vulnerability, CVE-2026-65400, has been found in macOS Screen Sharing, allowing attackers to bypass authentication.
- CISA, the U.S. cybersecurity agency, increased the severity rating from 7.1 to 9.8 (Critical) after discovering active exploitation.
- Hackers are using this vulnerability to gain Root access and install stealthy Monero cryptocurrency mining software on compromised machines.
macOS users must update immediately! The National Cyber Security Centre of the Netherlands (NCSC-NL) issued a warning on August 12 regarding widespread attacks exploiting CVE-2026-65400 in macOS Screen Sharing. The targets are Mac machines with Port 5900 exposed to the public.
The vulnerability is an Authentication Bypass, meaning attackers can remotely control a machine without requiring a valid username or password. In all reported cases, hackers have gained Root Access and installed Monero cryptocurrency mining software, using the victim's machine resources to generate revenue.
π» Re-evaluated Severity
Initially, this vulnerability was rated 7.1 by CISA. However, after the disclosure of Proof-of-Concept code and the discovery of widespread real-world attacks, CISA reviewed and increased the severity rating to 9.8 (Critical) on August 14. This re-evaluation was based on the assessment that the attack can be automated, requires no initial privileges, and completely impacts the confidentiality, integrity, and availability of data.
π‘οΈ Fixes and Prevention
Apple released an emergency out-of-band patch on August 6 to address this vulnerability in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. While this was a rapid response, many users may not have updated yet. For those unable to update immediately, it is advised to temporarily disable the Screen Sharing feature by navigating to System Settings > General > Sharing and turning off Screen Sharing.
π¬ Have you updated your macOS to the latest version to close this vulnerability? Or how often do you typically use the Screen Sharing feature? Share your thoughts!