MacOS Screen Sharing authentication bypass actively exploited (CVE-2026-65400)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-65400 in macOS Screen Sharing is being actively exploited on systems with TCP port 5900 exposed to the internet, allowing network attackers to bypass authentication and reach the desktop without credentials. Reported intrusions escalated to root access and Monero mining on exposed systems. Apple fixed the flaw on August 6 and released patched macOS versions, while defenders are being urged to update or disable Screen Sharing if it is not needed.
Related Happenings
PAN-OS GlobalProtect CVE-2026-0257 exploitation wave
Exploitation Wave
H score18
First: 01.06.2026 11:30
Last: 01.06.2026 11:30
Sources 1
About this happening:
CVE-2026-0257 is a Palo Alto Networks PAN-OS GlobalProtect authentication bypass that enabled unauthenticated VPN access on affected portal and gateway components....
PAN-OS GlobalProtect CVE-2026-0257 exploitation wave
Exploitation WaveAbout this happening: CVE-2026-0257 is a Palo Alto Networks PAN-OS GlobalProtect authentication bypass that enabled unauthenticated VPN access on affected portal and gateway components....
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/Mitigation
H score46
First: 20.02.2026 19:02
Last: 20.02.2026 19:02
Sources 1
About this happening:
CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/MitigationAbout this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA updates KEV entry for CVE-2026-1731
Public Sector Action
H score36
First: 20.02.2026 17:45
Last: 20.02.2026 17:45
Sources 1
About this happening:
CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...
CISA updates KEV entry for CVE-2026-1731
Public Sector ActionAbout this happening: CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...
BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave
Exploitation Wave
H score76
First: 12.02.2026 23:34
Last: 12.02.2026 23:34
Sources 1
About this happening:
CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...
BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave
Exploitation WaveAbout this happening: CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...
Timeline
-
14.08.2026 17:59 1 articles · 1h ago
Apple patches CVE-2026-65400 in macOS Screen Sharing
Mitigation Patch UpdateApple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier releases, and later recommended upgrading to macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9 to prevent rogue authentication attempts in macOS Screen Sharing.
Show sources
- Hackers exploit macOS Screen Sharing flaw to deploy Monero miner — www.bleepingcomputer.com — 14.08.2026 17:59
-
14.08.2026 17:59 2 articles · 1h ago
NCSC warns that CVE-2026-65400 is being actively exploited
Initial DisclosureThe Netherlands' National Cyber Security Centre warned that CVE-2026-65400 in macOS Screen Sharing was being actively abused on multiple systems with TCP port 5900 exposed to the internet after public exploit code emerged; attackers bypassed credentials, obtained root access, and deployed a Monero cryptocurrency miner.
Show sources
- Hackers exploit macOS Screen Sharing flaw to deploy Monero miner — www.bleepingcomputer.com — 14.08.2026 17:59
- Hackers exploit macOS Screen Sharing flaw to deploy Monero miner — www.bleepingcomputer.com — 14.08.2026 17:59