CVE-2026-65400Active Exploitation(apple / macos)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 45 mentions and remains active

Immediate actions

  • Patch apple macos systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-21. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-287

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos

Threat summary

  • Active exploitation appears in 130 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 197 mentions across 27 observed days

What's happening

  • Active exploitation reported across 130 signals
  • Exploit tool or code specified in 11 signals
  • PoC mentioned or linked in 31 signals
  • Patch or workaround mentioned in 120 signals
  • Technical details provided in 138 signals
  • General: 16 classified signals
  • Peaked 15d ago at 45 mentions (2026-08-17); latest day: 1
  • 197 total mentions across 27 days

Affected systems

Vendors
Products
macos

Deep dive

Activity timeline197 mentions / 27d
011233445Mentions · 2026-08-06: 4Mentions · 2026-08-07: 7Mentions · 2026-08-08: 11Mentions · 2026-08-09: 5Mentions · 2026-08-10: 3Mentions · 2026-08-11: 2Mentions · 2026-08-12: 2Mentions · 2026-08-13: 2Mentions · 2026-08-14: 5Mentions · 2026-08-15: 22Mentions · 2026-08-16: 14Mentions · 2026-08-17: 45Mentions · 2026-08-18: 18Mentions · 2026-08-19: 24Mentions · 2026-08-20: 6Mentions · 2026-08-21: 4Mentions · 2026-08-22: 4Mentions · 2026-08-23: 2Mentions · 2026-08-24: 6Mentions · 2026-08-26: 2Mentions · 2026-08-27: 2Mentions · 2026-08-28: 1Mentions · 2026-08-29: 2Mentions · 2026-08-30: 1Mentions · 2026-09-01: 1Mentions · 2026-09-04: 1Mentions · 2026-09-09: 1PoC Mentioned / Linked · 2026-08-08: 3PoC Mentioned / Linked · 2026-08-09: 1PoC Mentioned / Linked · 2026-08-12: 1PoC Mentioned / Linked · 2026-08-15: 1PoC Mentioned / Linked · 2026-08-16: 3PoC Mentioned / Linked · 2026-08-17: 10PoC Mentioned / Linked · 2026-08-18: 2PoC Mentioned / Linked · 2026-08-19: 3PoC Mentioned / Linked · 2026-08-20: 3PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-22: 1PoC Mentioned / Linked · 2026-08-24: 2Exploit Tool / Code · 2026-08-08: 1Exploit Tool / Code · 2026-08-16: 1Exploit Tool / Code · 2026-08-17: 2Exploit Tool / Code · 2026-08-19: 2Exploit Tool / Code · 2026-08-20: 3Exploit Tool / Code · 2026-08-22: 1Exploit Tool / Code · 2026-08-24: 1Active Exploitation · 2026-08-13: 1Active Exploitation · 2026-08-14: 5Active Exploitation · 2026-08-15: 20Active Exploitation · 2026-08-16: 14Active Exploitation · 2026-08-17: 40Active Exploitation · 2026-08-18: 16Active Exploitation · 2026-08-19: 16Active Exploitation · 2026-08-20: 5Active Exploitation · 2026-08-21: 2Active Exploitation · 2026-08-22: 1Active Exploitation · 2026-08-23: 2Active Exploitation · 2026-08-24: 3Active Exploitation · 2026-08-26: 1Active Exploitation · 2026-08-27: 1Active Exploitation · 2026-08-29: 2Active Exploitation · 2026-09-04: 1Patch / Workaround · 2026-08-06: 2Patch / Workaround · 2026-08-07: 6Patch / Workaround · 2026-08-08: 10Patch / Workaround · 2026-08-09: 2Patch / Workaround · 2026-08-10: 2Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-12: 2Patch / Workaround · 2026-08-13: 2Patch / Workaround · 2026-08-14: 3Patch / Workaround · 2026-08-15: 10Patch / Workaround · 2026-08-16: 10Patch / Workaround · 2026-08-17: 32Patch / Workaround · 2026-08-18: 9Patch / Workaround · 2026-08-19: 9Patch / Workaround · 2026-08-20: 4Patch / Workaround · 2026-08-21: 2Patch / Workaround · 2026-08-22: 2Patch / Workaround · 2026-08-23: 2Patch / Workaround · 2026-08-24: 3Patch / Workaround · 2026-08-26: 2Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-28: 1Patch / Workaround · 2026-08-29: 1Patch / Workaround · 2026-08-30: 1Patch / Workaround · 2026-09-04: 1Technical Details · 2026-08-06: 2Technical Details · 2026-08-07: 7Technical Details · 2026-08-08: 10Technical Details · 2026-08-09: 4Technical Details · 2026-08-10: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-12: 1Technical Details · 2026-08-13: 2Technical Details · 2026-08-14: 4Technical Details · 2026-08-15: 14Technical Details · 2026-08-16: 12Technical Details · 2026-08-17: 31Technical Details · 2026-08-18: 12Technical Details · 2026-08-19: 17Technical Details · 2026-08-20: 3Technical Details · 2026-08-21: 3Technical Details · 2026-08-23: 2Technical Details · 2026-08-24: 5Technical Details · 2026-08-26: 2Technical Details · 2026-08-27: 2Technical Details · 2026-08-28: 1Technical Details · 2026-08-29: 1Technical Details · 2026-09-01: 108-0608-0808-1008-1208-1408-1608-1808-2008-2208-2408-2708-2909-0109-09
Signal classification6 categories
Active Exploitation
12563.8%
Patch
3517.9%
General
168.2%
Disclosure
105.1%
PoC
84.1%
Exploit
21.0%
Referenced assets144 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-064
General2Patch2
2026-08-077
Disclosure1Patch6
2026-08-0811
Disclosure1General1Patch6PoC3
2026-08-095
Disclosure2Patch2PoC1
2026-08-103
General1Patch2
2026-08-112
Patch2
2026-08-122
Patch1PoC1
2026-08-132
Active Exploitation1Patch1
2026-08-145
Active Exploitation5
2026-08-1522
Active Exploitation20General1
2026-08-1614
Active Exploitation14
2026-08-1745
Active Exploitation39Patch4PoC2
2026-08-1818
Active Exploitation15General2Patch1
2026-08-1924
Active Exploitation15Disclosure2Exploit1General3Patch3
2026-08-206
Active Exploitation4Disclosure1General1
2026-08-214
Active Exploitation2Disclosure1General1
2026-08-224
Active Exploitation1General1Patch1PoC1
2026-08-232
Active Exploitation2
2026-08-246
Active Exploitation3Exploit1General2
2026-08-262
Active Exploitation1Patch1
2026-08-272
Active Exploitation1Patch1
2026-08-281
Disclosure1
2026-08-292
Active Exploitation2
2026-08-301
Patch1
2026-09-011
Disclosure1
2026-09-041
Patch1
2026-09-091
General1
Full discourse20 posts
  • Calif@calif_io
    PoC

    PoC for a critical vulnerability in Apple macOS Screen Sharing (CVE-2026-65400). If Screen Sharing is enabled, any network attacker can exploit the bug to log in as any account, without knowing the password. We reverse engineered Apple’s unusual macOS 26.6.1 patch to understand the root cause and exploitation path. Please upgrade your macOS boxes to 26.6.1. Full technical writeup drops tomorrow.

    Post summary

    A PoC for CVE-2026-65400 has been released, showing attackers can log into any macOS user account via Screen Sharing without a password; patch guidance is provided and technical details will follow.

    29423463.0K1.3K455.1K
    7.1K followersView on X
  • International Cyber Digest@IntCyberDigest
    Patch

    ❗️ Apple pushed an out-of-band macOS patch: a Screen Sharing vulnerability let an attacker on the network authenticate without valid credentials. Dubbed CVE-2026-65400, fixed in Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. https://support.apple.com/en-us/148170 https://t.co/QwxMjoUILP

    Post summary

    The post reports Apple’s out‑of‑band patch for CVE‑2026‑65400, noting the affected macOS versions and providing the official fix link.

    842345210745.1K
    227.0K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Four Critical Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824 Reported attacks include Monero mining, persistent access, and Babuk-derived ransomware. Read: https://thehackernews.com/2026/08/critical-macos-sharepoint-vcenter-and.html

    Post summary

    The post reports four CVEs that are currently being exploited in the wild, with associated Monero mining, ransomware, and persistent access attacks, and links to a news article for further details.

    410133339652.7K
    2.4M followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ Attackers are exploiting a macOS Screen Sharing flaw to install Monero miners. CVE-2026-65400 is being abused on multiple Macs exposing port 5900 to the internet. Apple patched the flaw in emergency macOS updates. What you need to know: https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html

    Post summary

    Attacker exploitation of CVE-2026-6540 is confirmed on macOS Screen Sharing via port 5900, with Apple issuing emergency patches to mitigate the issue.

    127192817880.3K
    2.4M followersView on X
  • Microsoft Threat Intelligence@MsftSecIntel
    Active Exploitation

    Microsoft Defender is monitoring the active exploitation of the CVE-2026-65400 improper authentication vulnerability on a limited number of macOS devices, with telemetry showing successful root account network sign-ins through Screen Sharing. Microsoft urges customers to immediately apply security updates and to investigate related Microsoft Defender alerts and detections. After gaining access, the attackers transferred files (scripts and a Secure Shell (SSH) public key) to the devices through Screen Sharing, established SSH persistence, removed histories and logs, modified Packet Filter settings, and deployed the cryptocurrency miner XMRig 6.26.0. They copied and ad-hoc signed XMRig as a hidden .config/sysmond binary, masqueraded it as com[.]apple[.]airportd, and persisted it with a KeepAlive LaunchDaemon. Indicators of compromise (IOCs): - SHA-256: 84006055916e267f7c2f9324f1848563e589e4526a296d4e9e9ce8e2112d357c (customized XMRig binary produced on multiple affected devices after the stock miner binary was copied, renamed to sysmond, and ad-hoc signed) - /private/var/root/.config/sysmond (hidden path used for the customized miner) - /Library/LaunchDaemons/com.xmr.miner.plist (malicious RunAtLoad and KeepAlive persistence) - exec -a com[.]apple[.]airportd (command-line masquerading used to present the miner as an Apple process) - 4AUZ9XNsffcPn13Yjk5yWAaZg8x5Fgu9cL9kWwDCnmACUFLuwrLg41WU31qiKfmo9ee62mVbwG9F5G82Ko8vck8nCtxdicj (Monero wallet reused across the observed deployments) - auto[.]c3pool[.]org:443 (mining-pool endpoint used by the miner; treat as contextual because mining pools may also receive legitimate traffic) The stock XMRig binary and its legitimate GitHub release URL should not be treated as malicious without the surrounding adversary technique context. Microsoft Defender alerts and detections: - 'CoinMiner' malware was prevented (Investigate retained SSH access, hidden miner copies, and com.xmr.miner.plist, even when quarantine succeeds) - Suspicious file or content ingress (Inspect the responsible process, destination, signing state, and nearby persistence) - Suspicious connection to remote service (Investigate unexpected root SSH sessions and sshd-session -i -R) When hunting, higher-confidence signals combine root-level Screen Sharing file transfer activity through SSFileCopyReceiver with writes to privileged .ssh, /private/etc, hidden /private/var/tmp, or LaunchDaemon paths. Microsoft recommends updating macOS to at least Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9; disabling unnecessary Screen Sharing; blocking untrusted TCP/5900 access; inspecting SSH keys and LaunchDaemons; removing unauthorized persistence; and rotating affected credentials.

    Post summary

    Microsoft confirms active exploitation of CVE-2026-65400 on macOS devices, with attackers leveraging Screen Sharing for authentication bypass and deploying a cryptocurrency miner. Users are advised to patch, disable Screen Sharing, and inspect for persistence.

    66351849643.6K
    197.4K followersView on X
  • Keystone Hardware Wallet@KeystoneWallet
    Active Exploitation

    Your Mac is probably mining crypto for someone else right now 🪙 CVE-2026-65400 (CVSS 9.8) is being actively exploited. Attackers are getting root access on Macs with Screen Sharing exposed to the internet, then quietly planting Monero miners on them. Your CPU runs hot. Your battery drains. You don't notice. They profit. But mining is just what's been observed so far. With root privileges, they also have access to your clipboard, local files, credentials, and any software wallet running on the machine. Patch. Check. Close. 🔹 Update macOS now to install the latest security patch 🔹 Open Activity Monitor and look for processes hogging CPU with no obvious reason 🔹 Turn off Screen Sharing when you're not using it. Never expose port 5900 to the internet

    Post summary

    CVE-2026-65400 is actively abused on Macs via exposed Screen Sharing, granting attackers root access and allowing them to run Monero miners and steal sensitive data; users are urged to patch macOS, inspect processes, and disable unnecessary sharing.

    42411155518.8K
    65.5K followersView on X
  • Goku 🗞@Crypto__Goku
    Active Exploitation

    ⚠️ Des hackers exploitent activement une faille de macOS pour prendre le contrôle de Mac… puis les transformer en machines à miner du Monero. La vulnérabilité CVE-2026-65400 touchait la fonction de partage d’écran de macOS. Des Mac exposant le port VNC 5900 sur Internet pouvaient être compromis sans authentification, permettant ensuite aux attaquants d’obtenir un accès root et d’installer un mineur de cryptomonnaie Monero à l’insu du propriétaire. Apple a corrigé la faille le 6 août avec macOS Tahoe 26.6.1, Sequoia 15.7.9 et Sonoma 14.8.9, mais le NCSC néerlandais avertit que des attaques sont déjà en cours. Si votre Mac n’est pas à jour, mieux vaut installer le correctif au plus vite ou désactiver temporairement le partage d’écran.

    Post summary

    CVE-2026-65400 is actively exploited on macOS systems with exposed VNC, granting root access for Monero mining; Apple has released patches and users should update or disable screen sharing immediately.

    2210953122.0K
    113.9K followersView on X
  • biren888.eth@biren888
    Active Exploitation

    Mac 用户也得注意了。 荷兰国家网络安全中心警告,黑客正在利用 macOS「屏幕共享」漏洞入侵暴露在互联网中的 Mac,并获取 root 权限,随后安装门罗币(XMR)挖矿程序。该漏洞编号为 CVE-2026-65400,严重性已被评估为 9.8/10。 苹果已经发布补丁。 如果你的 Mac 开启了屏幕共享,建议立即更新系统。 现在的黑客,连你的电脑算力都不放过。

    Post summary

    A severe macOS screen‑sharing vulnerability (CVE‑2026‑65400) is actively exploited to install XMR miners, but Apple has issued a patch and urges users to update immediately.

    750028011.3K
    41.9K followersView on X
  • Mr. Macintosh@ClassicII_MrMac
    Active Exploitation

    We might see the macOS Tahoe 26.6.2 update as soon as today.🔐✅ Note about CVE-2026-65400 🚨 NCSC Update: The NCSC has received a report showing that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet https://t.co/jdpRrOqzsC

    Post summary

    The NCSC reports active exploitation of CVE-2026-65400 on multiple systems with port 5900 exposed to the Internet.

    310061126.2K
    20.0K followersView on X
  • Md Ismail Šojal 🕷️@0x0SojalSec
    Patch

    If Screen Sharing is on, an attacker doesn’t need your password anymore. 🔥 Attacker on the network can authenticate as any local account without a password. CVE-2026-65400 : Pre-auth remote login on macOS Screen Sharing, Root cause: state machine desync in the authentication flow. Just enable Screen Sharing to attacker owns the session. Patch now (26.6.1 / 15.7.9 / 14.8.9) or disable Screen Sharing. https://x.com/calif_io/status/2086022794840793454/video/1

    Post summary

    CVE‑2026‑65400 allows network attackers to log in to macOS Screen Sharing without a password; a patch is available and should be applied immediately.

    16046283.2K
    55.7K followersView on X
  • Keystone 中文@KeystoneCN
    Active Exploitation

    你的 Mac 可能正在当“黄金矿工”,而你毫不知情 😰 macOS 屏幕共享漏洞 CVE-2026-65400 正遭到实际利用,CVSS 严重性评分已升至 9.8。攻击者已针对将屏幕共享服务暴露在公网的 Mac 获取 root 权限,并植入门罗币挖矿程序。 这类恶意程序或许不直接碰你的钱包,却会持续占用 CPU,让设备发热、变慢并增加功耗。 更值得警惕的是:攻击者已经获得了系统级权限,挖矿只是目前观察到的攻击方式之一。被入侵的电脑还可能进一步暴露剪贴板、本地文件、账户凭据,甚至威胁运行在电脑上的软件钱包。 你的行动清单: 🔹 立即更新 macOS,安装最新安全补丁 🔹 利用「活动监视器」,定期检查长期占用 CPU / 能耗异常的陌生进程 🔹 不使用「屏幕共享」时直接关闭,尤其不要将 5900 端口暴露到公网

    Post summary

    The macOS screen‑sharing flaw CVE‑2026‑65400 is reportedly being exploited in the wild to gain root access and deploy a Monero miner; users are urged to update the OS immediately.

    4910733.0K
    9.1K followersView on X
  • Brainrot Labs@Brainrot_Labs
    Active Exploitation

    🚨 Mac users: update now. Your Mac could be mining Monero for someone else. 💀 Apple đã vá CVE-2026-65400, một lỗ hổng nghiêm trọng trong macOS Screen Sharing đang bị attacker khai thác thực tế. Theo NCSC Hà Lan: 🔓 Mac có port 5900 exposed ra Internet có thể bị attacker khai thác 💻 Lỗ hổng cho phép kết nối chưa xác thực được coi như đã xác thực 👑 Attacker có thể giành root access ⛏️ Sau đó cài Monero miner để dùng CPU của máy nạn nhân đào XMR 🚨 CVSS: 9.8/10 Huntress xác định vấn đề nằm ở quá trình Secure Remote Password (SRP) của Screen Sharing. Đáng chú ý, đổi password hoặc tắt legacy VNC không đủ để giảm thiểu lỗ hổng. Apple đã phát hành bản vá ngày 6/8 cho: 🍎 macOS Tahoe 26.6.1 🍎 Sequoia 15.7.9 🍎 Sonoma 14.8.9 You: “My Mac is just sitting there.” Hacker: “Perfect. Let’s make it mine a little.” 💀⛏️ Nếu không cần Screen Sharing → tắt nó. Nếu đang dùng → update macOS ngay, đặc biệt với các máy Mac bare-metal đang được hosting. Một chiếc Mac chưa update + port 5900 public = máy đào Monero monero:native miễn phí cho hacker. 💀 Anh em check Mac của mình chưa? 👀 #BrainrotCrypto #DigitalSchizophrenia https://x.com/Brainrot_Labs/status/2089098121162666110?s=20

    Post summary

    Apple has released a patch for CVE‑2026‑65400, a critical macOS Screen Sharing vulnerability that is actively being used to install Monero miners on machines with port 5900 exposed; users must update or disable VNC to mitigate the risk.

    2200250675
    21.5K followersView on X
  • ثامر الغالي@alghali
    PoC

    🚨 تحذير أمني لمستخدمي الماك 🚨 تم توفير إثبات استغلال (PoC) لثغرة حرجة (CVE-2026-65400) في خاصية مشاركة الشاشة (Screen Sharing) بنظام macOS. ⚠️ الخطر: إذا كانت الخاصية مفعلة، يستطيع أي مهاجم على الشبكة تسجيل الدخول بأي حساب دون الحاجة لكلمة مرور! قاموا بعمل هندسة عكسية لتحديث أبل (macOS 26.6.1) غير المعتاد لفهم جذور المشكلة ومسار الاستغلال. 💡 الخطوة المطلوبة: بادر بتحديث أجهزتك إلى الإصدار 26.6.1 فوراً. https://x.com/calif_io/status/2086022794840793454/video/1

    Post summary

    A PoC for CVE-2026-65400 affecting macOS Screen Sharing has been released, enabling attackers to log in without passwords; users are urged to update to macOS 26.6.1 immediately.

    03025167.0K
    93.4K followersView on X
  • CiberBaur@BotBauR
    Active Exploitation

    🔴 Un CVE crítico está siendo explotado a nivel global: macOS Screen Sharing Flaw permite a hackers desplegar mineros de Monero en Macs con el puerto 5900 expuesto en línea. La vulnerabilidad CVE-2026-65400, con una puntuación CVSS de 9.8, está siendo activamente explotada menos de dos semanas después de que Apple lanzara el parche. El ataque aprovecha la vulnerabilidad en macOS para obtener acceso root y desplegar mineros de Monero en los sistemas afectados. El Centro Nacional de Ciberseguridad de los Países Bajos confirmó la explotación activa de esta vulnerabilidad crítica. Los sistemas afectados pueden tener sus recursos comprometidos para minar criptomonedas, lo que puede llevar a un aumento significativo en el consumo de energía y una disminución en el rendimiento del sistema. ¿Hay parche? Sí, Apple lanzó un parche para esta vulnerabilidad. ¿Qué deben hacer los afectados HOY? Revisar si tienen el puerto 5900 expuesto y aplicar el parche de seguridad lo antes posible. ¿Estás en riesgo? Revisa esto: configura el firewall para bloquear el tráfico entrante en el puerto 5900 y aplica las actualizaciones de seguridad de Apple. #Ciberseguridad #CVE #SeguridadDigital #Threat https://securityaffairs.com/197234/uncategorized/macos-screen-sharing-flaw-exploited-to-deploy-monero-miners.html

    Post summary

    CVE-2026-65400 is a critical macOS Screen Sharing flaw with CVSS 9.8 that is openly exploited worldwide to deploy Monero miners; Apple has issued a patch, and users should apply it immediately or block port 5900.

    0602261.3K
    629 followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    🍎 🚨 macOS Screen Sharing Auth Bypass: Underground Actor Shares ~24K Exposed Hosts A threat actor on an underground forum has published a list allegedly containing approximately 24,000 internet-accessible hosts potentially relevant to CVE-2026-65400, the recently disclosed Apple macOS Screen Sharing authentication-bypass vulnerability. * CVE-2026-65400 affects the built-in macOS Screen Sharing functionality * The vulnerability can allow a network attacker to authenticate to Screen Sharing without valid credentials * CISA now lists CVE-2026-65400 in its Known Exploited Vulnerabilities (KEV) Catalog * CISA currently rates the vulnerability CVSS 9.8 (Critical) and identifies active exploitation * The underground post provides a downloadable list allegedly containing ~24,000 hosts identified through exposed VNC/Apple Remote Desktop services on TCP/5900 * The actor also references publicly available proof-of-concept material * Importantly, the ~24K systems should be treated as potentially exposed hosts — NOT 24,000 confirmed vulnerable or compromised Macs ⚠️ Active Exploitation: This is no longer only theoretical. Reporting from the Netherlands indicates exploitation against internet-accessible systems with port 5900 exposed, including incidents where attackers obtained root access and deployed Monero cryptocurrency miners. ⚠️ Analyst Note: The underground distribution of precompiled target lists can substantially lower the reconnaissance barrier for opportunistic attackers. Organizations should immediately identify internet-exposed Screen Sharing/VNC services and update affected Macs. Patched versions: * macOS Tahoe 26.6.1 * macOS Sequoia 15.7.9 * macOS Sonoma 14.8.9 #DDW #Apple #macOS #CVE202665400 #Vulnerability #Cybersecurity #ThreatIntelligence

    Post summary

    An underground forum released a list of ~24K internet‑exposed macOS Screen Sharing hosts linked to CVE‑2026‑65400, with confirmed active exploitation including root compromise and cryptocurrency mining. Patched operating system versions are provided and immediate mitigation is advised.

    0501897.3K
    204.5K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-65400 Vendor: Apple Product: macOS Description: An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. Link: https://github.com/panchocosil/cve-2026-65400-poc #dbugs_vuln

    Post summary

    A functional PoC/exploit for CVE‑2026‑65400 has been publicly disclosed, demonstrating an authentication bypass to Screen Sharing, with Apple providing fixes in recent macOS releases.

    1302071.4K
    3.5K followersView on X
  • White Rhino Marketing@whitee_rhinoo
    Active Exploitation

    #Hackers are exploiting a critical #macOS Screen Sharing vulnerability (CVE-2026-65400) to gain root access and mine #Monero on compromised Macs. Over 40,000 devices with open ports were exposed, and #security researchers built working exploits using #AI in just 4 hours. Update macOS now. #MarketUpdate #StockMarket #USA #stocks #Bullish #bearish #TRUMP $Trump #America #DonaldTrump #rates #GlobalTrade #altcoin #altcoins #altseason #coin #coins #token #cryptocurrency #UnitedStates #XMR $XMR #AAPL $AAPL

    Post summary

    The text reports that CVE‑2026‑65400 is actively being exploited on macOS to gain root privileges and mine Monero, with researchers developing AI‑driven exploits; users are urged to update macOS.

    270160101
    1.1K followersView on X
  • NullSecurityX@NullSecurityX
    PoC

    PoC for a critical vulnerability in Apple macOS Screen Sharing (CVE-2026-65400). https://t.co/wf7ifZERlu

    Post summary

    A proof‑of‑concept for CVE‑2026‑65400, a critical macOS Screen Sharing vulnerability, has been published with an accompanying link.

    0111741.7K
    12.2K followersView on X
  • boubacar36@boubakar58577
    Active Exploitation

    ⚠️ Des hackers exploitent activement une faille de macOS pour prendre le contrôle de Mac… puis les transformer en machines à miner du Monero. La vulnérabilité CVE-2026-65400 touchait la fonction de partage d’écran de macOS. Des Mac exposant le port VNC 5900 sur Internet pouvaient être compromis sans authentification, permettant ensuite aux attaquants d’obtenir un accès root et d’installer un mineur de cryptomonnaie Monero à l’insu du propriétaire. Apple a corrigé la faille le 6 août avec macOS Tahoe 26.6.1, Sequoia 15.7.9 et Sonoma 14.8.9, mais le NCSC néerlandais avertit que des attaques sont déjà en cours. Si votre Mac n’est pas à jour, mieux vaut installer le correctif au plus vite ou désactiver temporairement le partage d’écran.

    Post summary

    CVE‑2026‑65400 is being actively exploited in the wild to gain root on macOS via the VNC/Screen‑Sharing service, and Apple has issued patches (macOS Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9). Users should update immediately or disable the affected feature.

    060911.2K
    1.2K followersView on X
  • 𝐿𝑖𝑛𝑢𝑥 𝑢𝑠𝑒𝑟@linuxuser1996
    Active Exploitation

    Your Mac’s Screen Sharing had a pre-auth bypass. No password, no credentials, straight to root. CVE-2026-65400 is being exploited in the wild right now. Dutch NCSC found compromised machines running Monero miners. Patched Aug 6. If you’re on Sonoma, Sequoia, or Tahoe and haven’t updated, do it now. Not updating? System Settings → General → Sharing → kill Screen Sharing.

    Post summary

    A pre‑authentication bypass in macOS Screen Sharing (CVE‑2026‑65400) is actively exploited in the wild, prompting users to update or disable the service.

    0201031.0K
    3.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---

Explore more