Apple has released security updates to patch a critical zero-day vulnerability in its macOS Screen Sharing feature, tracked as CVE-2026-65400. Rated with a CVSS severity score of 9.8 out of 10, the flaw allows unauthenticated remote attackers to obtain root-level access on vulnerable systems. According to advisories from security researcher Alfredo Pesoli and the Dutch National Cyber Security Centre (NCSC-NL), the flaw stems from improper state management within the Secure Remote Password authentication process in the Screen Sharing daemon. Threat actors are actively scanning the internet for exposed systems on default port 5900, bypassing authentication to install unauthorized Monero cryptocurrency miners. Apple addressed the flaw in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. Cybersecurity authorities strongly urge administrators and personal users to apply the updates immediately, disable exposed Screen Sharing services, or restrict port 5900 access behind segmented virtual private networks.
Prepared by Jonathan Pierce and reviewed by editorial team.
Left: Framing emphasizes consumer risk and corporate software security maintenance responsibilities. Center: Framing focuses on technical facts, CVE details, and patch deployment. Right: Framing highlights economic impacts, enterprise infrastructure risks, and cyber threat actors.
NCSC-NL published advisory confirming active abuse of macOS port 5900. https://www.ncsc.nl/actueel/advisories/ncsc-2026-0341
Apple issues urgent security patch for Mac Screen Sharing vulnerability
CNN Business Washington PostmacOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Security Affairs ReutersApple releases emergency patch for critical macOS zero-day flaw Associated Press Bloomberg TechCrunch Ars Technica Wired BleepingComputer The Verge CNBC Dark Reading SecurityWeek ZDNET The Register Cybersecurity Dive CSO Online Fox Business Forbes
Comments