Tech News · 18 August 2026

Apple Confirms Active Exploitation of Remote Access Vulnerability

Dutch cyber-security officials say attackers have used the patched macOS bug against internet-exposed Macs, gaining root access and installing crypto-mining software.

Legacy article - classification pending

What you need to know

  • CVE-2026-65400 has been used against multiple internet-exposed Macs, according to NCSC-NL.
  • Reported victims had root access taken over and a Monero cryptocurrency miner installed.
  • Apple issued fixes on 6 August for macOS Tahoe, Sequoia and Sonoma.

Apple’s recently patched macOS Screen Sharing vulnerability is now being exploited in the wild, according to the Netherlands’ National Cyber Security Centre (NCSC-NL). The agency said on 12 August that it had received reports of attacks against multiple Macs with TCP port 5900 accessible from the internet.

Laptop on a desk beside a home router
Reported attacks targeted Macs with TCP port 5900 accessible from the public internet.

In every case reported to NCSC-NL, attackers gained root access and installed a Monero cryptocurrency miner. That is a significant escalation from the previously reported risk: this is no longer solely a flaw demonstrated by security researchers, but one linked to attacks on real systems.

The vulnerability, tracked as CVE-2026-65400, was disclosed and fixed by Apple on 6 August. Apple said it was an authentication issue that could let “an attacker on the network” authenticate to Screen Sharing without valid credentials. The company said it addressed the problem through improved state management.

Internet-exposed Macs are the confirmed target

The reported attacks have an important qualification. NCSC-NL’s evidence concerns systems where port 5900, commonly used for Screen Sharing connections, was reachable from the public internet. It does not say that every Mac with Screen Sharing switched on has been attacked, nor does it confirm the level of risk for other network configurations.

But the consequences in the documented cases are serious. Root access gives an intruder extensive control over a Mac, while Engadget reported that the flaw could allow attackers to view a victim’s screen, open files and take broad control of the machine. NCSC-NL said the observed attackers installed Monero mining software, which uses a compromised computer’s resources to generate cryptocurrency.

The identity of the attackers or any group behind the activity has not been confirmed. Neither do the reviewed reports establish that passwords, banking information or other particular types of personal data were stolen in the incidents.

As previously reported, the weakness lies in macOS Screen Sharing, Apple’s remote-access infrastructure. Public proof-of-concept material for CVE-2026-65400 was available by 12 August, according to NCSC-NL. Engadget also reproduced an 8 August post from security researcher Calif, who said: “If Screen Sharing is enabled, any network attacker can exploit the bug to log in as any account, without knowing the password.”

Which Mac updates contain the fix?

Apple included fixes for CVE-2026-65400 in three releases issued on 6 August: macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. Apple’s security notes list the vulnerability under Screen Sharing for each of those versions.

  • macOS Tahoe: update to at least version 26.6.1; Apple’s UK update page lists macOS Tahoe 26.6.2, released on 17 August, as the latest version.
  • macOS Sequoia: update to macOS Sequoia 15.7.9.
  • macOS Sonoma: update to macOS Sonoma 14.8.9.

Apple’s UK security-updates page lists Tahoe 26.6.2 as the newest release, though the reviewed sources do not confirm whether it includes additional changes specifically related to CVE-2026-65400. The practical message is straightforward: install the newest applicable macOS update available for the Mac.

If an update cannot be applied immediately, the sources reviewed recommend disabling Screen Sharing and ensuring that port 5900 is not exposed to the internet. This is especially relevant for people who have deliberately configured remote access to a Mac from outside their home or workplace network.

A separate July flaw should not be confused with this one

Apple had already fixed another Screen Sharing Server issue on 27 July, identified as CVE-2026-43760, in macOS Tahoe 26.6, Sonoma 14.8.8 and Sequoia 15.7.8. Apple described that earlier bug as an access problem that could allow an app to access user-sensitive data.

Despite affecting related macOS infrastructure, it is a separate vulnerability. The August flaw, CVE-2026-65400, is the one tied by NCSC-NL to unauthorised authentication, attacks against internet-exposed port 5900 and the installation of Monero miners.

Why this matters beyond IT departments

For most UK Mac owners, this is not a reason to replace hardware or buy additional software. It is a reason not to postpone a system update. The confirmed attacks focused on publicly exposed machines, a setup more likely in small offices, home-working arrangements or enthusiast remote-access configurations than on a standard laptop left on a typical home network.

Still, the reported root-level access makes the flaw worth treating urgently. A Screen Sharing feature that is no longer needed should be disabled, and anyone who relies on it should make sure their Mac has the relevant security update before using it again. Apple credited Alfredo Pesoli, known as @__rev, via Bynario Atlas for reporting the issue.

Why it matters

This moves the Screen Sharing issue from a serious patching concern to a confirmed real-world threat, particularly for people who have made remote access available over the internet. Most ordinary Mac owners are not described as being part of the observed attack set, but anyone running an older version of Tahoe, Sequoia or Sonoma should update promptly and check that Screen Sharing is not unnecessarily exposed.