Overview
- Apple issued out‑of‑band fixes on Thursday, August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9 that patch CVE‑2026‑65400 by improving state management in Screen Sharing.
- The Netherlands’ NCSC updated its advisory on August 12 to confirm active exploitation of internet‑exposed Macs with port 5900 reachable, reporting attackers obtained root and installed Monero miners on affected machines.
- On August 14 the U.S. Cybersecurity and Infrastructure Security Agency reclassified the flaw to CVSS 9.8 and labeled exploitation automatable, reflecting that attackers need no privileges and can scale attacks.
- Security researchers and vendors say public proof‑of‑concept code and Black Hat demonstrations have lowered the bar for attackers, and scans by firms like Huntress found tens of thousands of potentially reachable Macs that could be at risk.
- Standard defenses such as changing Screen Sharing passwords do not stop this pre‑authentication bug, so responders should install Apple’s updates, disable Screen Sharing when not needed, block TCP port 5900 where possible and assume full compromise if root access is observed.