Back to advisories

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public exploitation.

CRITICALAdvisoryAug 16, 2026
Action required
Immediately identify all macOS systems with port 5900 exposed to the internet. Patch to the August 6 Apple security update or later. For systems that cannot be patched immediately, firewall port 5900 or disable Screen Sharing.
Affected products
macOSAppleScreen Sharing