Find notable cyber news and cases, enriched with sources, timelines, and signals.

MacOS Screen Sharing authentication bypass actively exploited (CVE-2026-65400)

Vulnerability
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-65400 in macOS Screen Sharing is being actively exploited on systems with TCP port 5900 exposed to the internet, allowing network attackers to bypass authentication and reach the desktop without credentials. Reported intrusions escalated to root access and Monero mining on exposed systems. Apple fixed the flaw on August 6 and released patched macOS versions, while defenders are being urged to update or disable Screen Sharing if it is not needed.

Related Happenings

PAN-OS GlobalProtect CVE-2026-0257 exploitation wave

Exploitation Wave
H score18 First: 01.06.2026 11:30 Last: 01.06.2026 11:30 Sources 1

About this happening: CVE-2026-0257 is a Palo Alto Networks PAN-OS GlobalProtect authentication bypass that enabled unauthenticated VPN access on affected portal and gateway components....

CISA KEV mitigation for BeyondTrust CVE-2026-1731

Advisory/Mitigation
H score46 First: 20.02.2026 19:02 Last: 20.02.2026 19:02 Sources 1

About this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...

CISA updates KEV entry for CVE-2026-1731

Public Sector Action
H score36 First: 20.02.2026 17:45 Last: 20.02.2026 17:45 Sources 1

About this happening: CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...

BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave

Exploitation Wave
H score76 First: 12.02.2026 23:34 Last: 12.02.2026 23:34 Sources 1

About this happening: CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...

Timeline

  1. 14.08.2026 17:59 1 articles · 1h ago

    Apple patches CVE-2026-65400 in macOS Screen Sharing

    Mitigation Patch Update

    Apple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier releases, and later recommended upgrading to macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9 to prevent rogue authentication attempts in macOS Screen Sharing.

    Show sources
  2. 14.08.2026 17:59 2 articles · 1h ago

    NCSC warns that CVE-2026-65400 is being actively exploited

    Initial Disclosure

    The Netherlands' National Cyber Security Centre warned that CVE-2026-65400 in macOS Screen Sharing was being actively abused on multiple systems with TCP port 5900 exposed to the internet after public exploit code emerged; attackers bypassed credentials, obtained root access, and deployed a Monero cryptocurrency miner.

    Show sources