ConicPlex

Start Your Project

A MacBook Pro sitting closed on a dark desk at night, lit by a faint blue glow

On this Page

A Critical macOS Screen Sharing Vulnerability Is Being Actively Exploited Right Now

Husen Memon

August 17, 2026

Apple patched a critical macOS Screen Sharing vulnerability on August 6, and for most sites, that would be the end of the story. It is not. The Netherlands’ national cyber security centre, NCSC-NL, updated its advisory on August 12 to confirm attackers are actively exploiting the flaw against Macs left reachable from the open internet, and coverage this week shows those attacks ending with a Monero cryptocurrency miner running as root. If you or anyone on your team has Screen Sharing turned on, this is worth five minutes today.

A MacBook Pro sitting closed on a dark desk at night, lit by a faint blue glow

What CVE-2026-65400 actually does

The bug lives in screensharingd, the system daemon behind macOS’s built-in remote desktop feature. Screen Sharing normally authenticates a connection using Secure Remote Password, a challenge-response scheme that is supposed to reject anyone who does not know the account password. According to the technical breakdown published by Apple and cross-referenced by security researchers, the daemon’s frame-length validator returned a stale success status under certain conditions, so the connection got waved through as authenticated even when it was not, and the session then continued in cleartext with no encryption. An attacker on the network, or anyone who could reach port 5900, could get in without ever knowing a password.

Apple credits Alfredo Pesoli of Bynario Atlas with the discovery and rates the issue critical, with third-party trackers scoring it at CVSS 9.8. Apple’s own advisory describes it more plainly: “an authentication issue was addressed with improved state management.”

Who is actually at risk

Exploitation requires two things to line up: Screen Sharing has to be turned on, and port 5900 has to be reachable from outside your local network. That second part is the one that matters most. NCSC-NL’s advisory is specific that the exploitation it observed hit systems with the port exposed directly to the internet, not machines sitting safely behind a home or office router with no port forwarding rules. Once an attacker got in, they gained root and dropped a Monero miner, according to the agency’s writeup.

What to do about it

  • Update to macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 (or whatever is current when you read this). Apple shipped the fix for all three branches on August 6.
  • If nobody outside your network needs to reach Screen Sharing, turn it off in System Settings under General, then Sharing.
  • Never forward port 5900 straight to the internet. If you genuinely need remote screen access, put it behind a VPN or an SSH tunnel instead.
  • If your Mac was internet-facing before you patched, open Activity Monitor and look for an unfamiliar process eating CPU. That is the tell for the miner payload NCSC-NL described.

None of this requires specialized tools, just five minutes in System Settings and a software update. Given that public proof-of-concept code is already circulating and NCSC-NL is still tracking active abuse, that five minutes is worth spending today rather than next week.

It has been a busy month for critical patches across the board. Earlier in August, WordPress shipped its own fix for a real remote code execution vulnerability in core. If you want the running list of what has shipped and what is still exploitable, we track it in our News & Updates coverage.

Sources

Husen Memon is a co-founder of ConicPlex, a web development agency specializing in WordPress, Webflow, and custom software builds. Over more than 9 years and 200+ client projects, he has worked across everything from plugin development to full platform migrations, with a focus on building sites and tools that hold up under real day-to-day use, not just in a demo. He writes here about the technical decisions and tradeoffs that come up in that work.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

Software

Marble consultation counter in a med spa with a tablet, orchid, treatment cards, and a towel, with a treatment room visible in the background

Why a Treatment-Finder Quiz Converts Better Than a Service Menu for Med Spas and Clinics

A treatment-finder quiz can convert far better than a static service list on a med spa or clinic website. Here…

Aftab Memon

September 12, 2026

Plugins

Illustration of a notification bell above a stack of product boxes, representing WooCommerce back in stock notification plugins

Best WooCommerce Back in Stock Notification Plugins: 4 Real Options Compared

WooCommerce has no built-in way to notify a customer when an out-of-stock product comes back. This post compares four real…

Husen Memon

September 11, 2026

News & Updates

A laptop glowing with soft blue, red, yellow, and green light beside a cracked glass cube on a desk, symbolizing a breached browser security boundary

Chrome Patches Its Seventh Actively Exploited Zero-Day of 2026 (CVE-2026-87491)

Google patched CVE-2026-87491, Chrome’s seventh actively exploited zero-day of 2026, in Chrome 153. Here’s what changed and how to update….

Sameer Malek

September 10, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant