A critical vulnerability in Apple's macOS, tracked as CVE-2026-65400, is under active exploitation by threat actors. The flaw is an authentication bypass in the native Screen Sharing feature, which allows a remote, unauthenticated attacker to gain full root-level control of a vulnerable Mac. The U.S. CISA has elevated the vulnerability's severity score to a critical 9.8 on the CVSS scale following confirmation of in-the-wild attacks. Attackers are scanning for and compromising Macs with the VNC port (5900) exposed to the internet, deploying Monero cryptomining malware post-exploitation. Apple has released patches, and immediate action is required to mitigate this threat.
The vulnerability resides in the authentication mechanism of the macOS Screen Sharing service, which uses the VNC protocol. Due to insufficient state management, an attacker can bypass the authentication process entirely and gain direct access to the system's desktop environment. As the Screen Sharing service can run with high privileges, this access can be immediately escalated to root, giving the attacker complete control over the device.
The vulnerability affects multiple versions of macOS. Apple released patches on August 6, 2026, for the following versions and later:
Any Mac running an older version with Screen Sharing or Remote Management enabled and exposed to the network (especially the internet) is considered vulnerable.
The Dutch National Cyber Security Centre (NCSC-NL) and CISA have confirmed that CVE-2026-65400 is being actively exploited in the wild. The attacks observed involve mass scanning for Macs with TCP port 5900 open. Once a vulnerable host is found, the attackers use the exploit to gain root access (T1068 - Exploitation for Privilege Escalation) and then deploy malware. The current payload is a Monero cryptominer, a form of T1496 - Resource Hijacking.
While the current payload is cryptojacking malware, which primarily impacts performance and energy consumption, the underlying access is far more dangerous. Full root access allows an attacker to:
The ease of exploitation (no authentication needed) and the level of access gained make this a critical threat to all exposed, unpatched Macs.
The following patterns may help identify vulnerable or compromised systems:
port5900process_namescreensharingdscreensharingd process.process_namexmr-stak, xmrig, c3pool_minercommand_line_patternHigh CPU usage by unexpected processes5900 open.5900 from the public internet. This configuration is highly discouraged and should be investigated immediately. This aligns with D3FEND's Network Traffic Analysis (D3-NTA).M1051 - Update Software.System Settings > General > Sharing. This is a critical compensating control, mapping to M1042 - Disable or Remove Feature or Program.5900 from untrusted networks. Access to Screen Sharing should be restricted to internal management subnets or through a VPN, as per M1035 - Limit Access to Resource Over Network.Public PoC exploit for CVE-2026-65400 released, accelerating widespread cryptomining attacks and increasing risk of more severe payloads.
Immediately apply the security updates provided by Apple to all vulnerable macOS devices.
Mapped D3FEND Techniques:
If patching is not possible, disable the Screen Sharing and Remote Management services as a critical compensating control.
Mapped D3FEND Techniques:
Block inbound access to TCP port 5900 at the network perimeter. Access should only be allowed from trusted internal networks or via VPN.
Mapped D3FEND Techniques:
Apple releases out-of-band security updates to patch CVE-2026-65400.
Reports emerge confirming active exploitation of the vulnerability in the wild.
CISA updates the CVSS score for CVE-2026-65400 to 9.8 (Critical).

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.