Apple has patched a security vulnerability in macOS Screen Sharing that could allow an attacker on the network to authenticate to the service without valid credentials. The vulnerability, tracked as CVE-2026-65400, has a CVSS score of 7.1 and is reportedly being actively exploited in attacks.
The issue affects macOS Tahoe, Sequoia and Sonoma. Apple addressed the vulnerability through security updates released on August 6.
macOS Screen Sharing Vulnerability Explained
According to the Netherlands National Cyber Security Centre (NCSC), CVE-2026-65400 is an authentication issue in macOS Screen Sharing. The flaw could allow a network attacker to authenticate to Screen Sharing without valid credentials.
The NCSC said it had received information about active exploitation on multiple systems where port 5900 was accessible from the internet. In the reported incidents, attackers obtained root access and installed a Monero cryptocurrency miner.
Apple describes the vulnerability as an authentication issue that was fixed through improved state management. The company lists the issue in its security updates for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.
Which macOS Versions Are Affected?
The vulnerability is associated with Apple’s Screen Sharing functionality on:
- macOS Tahoe
- macOS Sequoia
- macOS Sonoma
Apple released the following versions containing the security fix:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
Why Port 5900 Matters
The NCSC’s warning indicates that the reported attacks involved systems where TCP port 5900 was reachable from the internet. Port 5900 is commonly associated with remote desktop and Screen Sharing services.
Users who have Screen Sharing exposed directly to the internet could therefore face additional risk, particularly if their Mac has not received Apple’s security update.
How to Protect Your Mac
Mac users should install the latest security update available for their version of macOS.
Users who do not need Screen Sharing can also disable the feature by going to:
System Settings → General → Sharing → Screen Sharing → Off
It is also advisable to avoid exposing Screen Sharing services directly to the public internet.
Apple Security Update Recommended
Apple released the relevant security fixes on August 6, 2026. The company says the Screen Sharing authentication problem was addressed with improved state management.
With active exploitation now reported by the Dutch NCSC, Mac users should install the applicable security update as soon as possible, especially if Screen Sharing is enabled or port 5900 is accessible from the internet.
