THREAT actors are exploiting a newly patched macOS vulnerability, CVE-2026-65400, which enables remote access to systems via Screen Sharing without valid credentials. This high-severity flaw allows hackers to gain root access and deploy cryptominers. Apple released fixes on August 6, after which active exploitation was reported by the Dutch NCSC. The vulnerability can be triggered easily by naming an account, exposing around 40,000 internet-accessible macOS systems to potential attacks. Additionally, several other vulnerabilities in the same system component were patched recently.
Apple fixes macOS Screen Sharing bug exploited for crypto mining
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Apple Patches 273 Flaws as Screen Sharing Bug Faces Active Attacks
thezdi.com
-
Apple Patches Record 261 Flaws Across New Operating Systems
isc.sans.edu
-
Google patches Android ContactsProvider2 SQLi high severity bug
securityonline.info
-
Urgent Patches Address Flaws in Microsoft, Apple, IBM Db2
securityonline.info
-
Telegram seeks .gram domain as critical zero day exploits surge
securityonline.info
-
CISA warns of active exploits in Microsoft, VMware, Apple bugs
securityweek.com
-
U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog
securityaffairs.com
-
CISA KEV Adds Four Exploited Flaws in SharePoint, vCenter
securityonline.info
-
CISA flags macOS Screen Sharing bug CVE-2026-65400 as exploited
cisa.gov
-
CISA Adds CVE-2026-65400 to Known Exploited Vulnerabilities Catalogue
cisa.gov
-
Update your Mac: Screen Sharing vulnerability exploited in the wild
malwarebytes.com
-
Apple fixes macOS Screen Sharing bug exploited for crypto mining
www.securityweek.com
-
Hackers exploit CVE-2026-65400 to mine Monero on macOS
securityaffairs.com
-
Apple patches CVE-2026-65400 macOS flaw after crypto miner attacks
arstechnica.com