While Apple initially released emergency security updates as a precautionary measure, cybersecurity authorities—led by the Netherlands National Cyber Security Centrum (NCSC-NL)—have confirmed that attackers are actively exploiting unpatched systems.
Vulnerability Details
-
Identifier: Tracked as CVE-2026-65400.
-
The Flaw: An authentication-bypass bug caused by improper session state management.
-
Impact: Allows a remote attacker on a reachable network to gain full Screen Sharing access without requiring valid login credentials.
-
Real-World Exploitation: Attackers are scanning for systems with TCP Port 5900 exposed to the internet. Upon gaining access, bad actors escalate privileges to root level and deploy unauthorized Monero cryptocurrency miners and background scripts.
Affected Systems & Security Patches
Apple bypassed its usual public beta testing phases to release immediate security updates. Check your system version to ensure you are protected:
| macOS Version | Required Patch Version |
| macOS Tahoe | macOS Tahoe 26.6.1 or later |
| macOS Sequoia | macOS Sequoia 15.7.9 or later |
| macOS Sonoma | macOS Sonoma 14.8.9 or later |
Mandatory Remediation Steps
1. Install the Latest macOS Update Immediately
Navigate to System Settings $\rightarrow$ General $\rightarrow$ Software Update and install available updates right away.
2. Disable Screen Sharing (If Not Required)
Removing the service closes the attack vector entirely:
-
Open System Settings.
-
Click General $\rightarrow$ Sharing.
-
Toggle off Screen Sharing (and Remote Management, if enabled).
3. Secure Port 5900
Ensure your router or hardware firewall is not forwarding TCP port 5900 to the public internet. If remote access to your Mac is required, route connections through a private VPN or SSH tunnel rather than exposing the port directly.

