THE Dutch National Cyber Security Centre (NCSC) reported an exploitation of a vulnerability in Apple's Screen Sharing feature (CVE-2026-65400), allowing attackers to remotely control Macs without valid credentials. This vulnerability, patched by Apple on August 6, 2026, can lead to unauthorized installations of Monero cryptominers. Users are advised to update their Macs and disable Screen Sharing if not in use to mitigate risks. Active exploitation cases involve root access leading to potential data theft and deployment of further malware.
Update your Mac: Screen Sharing vulnerability exploited in the wild
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Apple Patches 273 Flaws as Screen Sharing Bug Faces Active Attacks
thezdi.com
-
Apple Patches Record 261 Flaws Across New Operating Systems
isc.sans.edu
-
Google patches Android ContactsProvider2 SQLi high severity bug
securityonline.info
-
Urgent Patches Address Flaws in Microsoft, Apple, IBM Db2
securityonline.info
-
Telegram seeks .gram domain as critical zero day exploits surge
securityonline.info
-
CISA warns of active exploits in Microsoft, VMware, Apple bugs
securityweek.com
-
U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog
securityaffairs.com
-
CISA KEV Adds Four Exploited Flaws in SharePoint, vCenter
securityonline.info
-
CISA flags macOS Screen Sharing bug CVE-2026-65400 as exploited
cisa.gov
-
CISA Adds CVE-2026-65400 to Known Exploited Vulnerabilities Catalogue
cisa.gov
-
Update your Mac: Screen Sharing vulnerability exploited in the wild
www.malwarebytes.com
-
Apple fixes macOS Screen Sharing bug exploited for crypto mining
securityweek.com
-
Hackers exploit CVE-2026-65400 to mine Monero on macOS
securityaffairs.com
-
Apple patches CVE-2026-65400 macOS flaw after crypto miner attacks
arstechnica.com