All incidents

Apple patches actively exploited macOS vulnerability CVE-2026-65400

vulnerabilityopenAug 7, 2026 — Aug 14, 2026
Apple patches actively exploited macOS vulnerability CVE-2026-65400

APPLE has issued a security update that addresses CVE-2026-65400, a flaw in the macOS screen sharing component. The flaw is presently being exploited in the wild according to Ars Technica.

The vulnerability carries a CVSS score of 9.8 and can be triggered when port 5900 is reachable from the internet, allowing an attacker to execute arbitrary code with the privileges of the screen sharing service. Successful exploitation has been observed delivering Monero cryptocurrency miners to compromised machines.

On the same day Apple released its fix, Microsoft published updates for several critical remote code execution flaws, including CVE-2026-63508, CVE-2026-56162 and CVE-2026-65667, each rated CVSS 10 as reported by SecurityWeek. These flaws affect Active Directory and Azure services, where missing authentication checks could let intruders run code with elevated privileges.

The Dutch NCSC advisory notes that the macOS flaw is under active attack. No specific threat actor has been linked to the campaigns so far according to the advisory.

Defenders should turn off screen sharing unless it is required, block inbound connections to TCP port 5900 at the perimeter, and apply the latest macOS security update without delay. Organizations should also verify that the update has been successfully installed across all managed devices.

Monitoring for unusual CPU spikes or unknown processes can help detect the presence of crypto miner payloads, and reviewing firewall logs for unexpected traffic to port 5900 will aid in early detection. Keeping all systems patched reduces the window for attackers to leverage known flaws.

Intelligence briefing updated Aug 14, 2026

CVE-2026-56162 10.0 CVE-2026-63508 10.0 CVE-2026-65667 10.0 CVE-2026-65400 9.8
Root sourceadvisories.ncsc.nl
Timeline Coverage

Swipe to explore timeline