Blog

This macOS Screen Sharing Bug Gives Attackers Root Access and It’s Being Exploited Right Now

Published August 27th, 2026 by Bayonseo

Attackers can now obtain complete root access to Macs without a password thanks to a serious macOS vulnerability that is actively being used in the wild. The vulnerability, known as CVE-2026-65400, has already been used to install cryptocurrency miners on compromised PCs and impacts Apple's built-in Screen Sharing feature.

Less than two weeks after Apple patched the issue on August 6, 2026, the Dutch National Cyber Security Center (NCSC-NL) confirmed active exploitation on several systems. You can't afford to ignore this security warning if you use a Mac, especially for work.


What Is CVE-2026-65400?

The vulnerability stems from a state management flaw in macOS Screen Sharing, a feature that enables remote control of a Mac over a network. Attackers can use the vulnerability to get around authentication and access a Mac without using legitimate credentials. Alfredo Pesoli, a security researcher at Bynario, found the vulnerability and notified Apple. Although other sources have given the bug a CVSS score of 9.8, a "critical" assessment, Apple has given it a severity level of 7.1 out of 10.

The problem arises when the default port for VNC-based screen sharing, 5900, is open to the internet. Attackers are actively looking for Macs with this port open, taking advantage of the authentication bypass, and obtaining root access to install Monero cryptocurrency miners, according to the NCSC-NL.


Who Is at Risk?

Any Mac that has port 5900 open to the internet and Screen Sharing enabled is susceptible. Although many users, especially IT administrators, developers, and remote workers, may have switched the feature on for convenience and forgotten about it, it is not enabled by default. Although port 5900 is often blocked by routers and firewalls, your Mac may be vulnerable if you have manually set up port forwarding or if your firewall rules are too lax.


What Attackers Are Doing Right Now

The NCSC-NL verified that attackers installed Monero miners and obtained root access in every instance that was seen. A kind of malware known as a Monero miner leverages the processing power of your Mac to mine cryptocurrency for the attacker, frequently resulting in slower systems and increased electricity costs. The same root access might be used to install more harmful malware, such as spyware, ransomware, or credential stealers, even if cryptocurrency mining may appear to be quite safe.


How to Protect Your Mac

Step 1: Install the security update right away.

CVE-2026-65400 was fixed by Apple in the following macOS versions:

  • Tahoe 26.6.1 for macOS
  • Sequoia 15.7.9 for macOS
  • Sonoma 14.8.9 for macOS

Install the most recent update by going to System Settings > General > Software Update. The most important step is this one.

Step 2: If you don't need screen sharing, disable it.

Turn off Screen Sharing completely if you don't use it frequently. Turn off the Screen Sharing option by going to System Settings > General > Sharing.

Step 3: Avoid Directly Exposing Port 5900 If You Must Use Screen Sharing

It is highly recommended by security professionals not to expose port 5900 to the internet. Instead, to remotely access your Mac, use SSH tunneling or a VPN, which add levels of encryption and authentication to prevent this attack.


How Bayon Technologies Group Can Help You Stay Safe

We at Bayon Technologies Group assist businesses in safeguarding their Mac fleets against vulnerabilities such as CVE-2026-65400. Among the services we offer are:

  • Vulnerability assessment and patch management: We make sure your systems are updated and given priority for important updates.
  • Security Reviews for Remote Access: We evaluate how your team connects remotely and get rid of dangerous habits like putting internal services online.
  • Continuous Monitoring: We use monitoring to find strange operations, unauthorized access, or bitcoin mining activity on your network.
  • Security Awareness Training: We teach your staff how to safely configure tools like Screen Sharing and the dangers of turning them on.

Don't allow a forgotten setting to compromise the entire system. To secure your Mac environment, get in touch with Bayon Technologies Group right now.


‹ Back