HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Attackers Exploit Patched macOS Screen Sharing Flaw (CVE‑2026‑65400) to Gain Root Access and Deploy Cryptominers

Threat actors are actively exploiting CVE‑2026‑65400, a macOS Screen Sharing authentication bypass, to obtain root privileges and install a Monero cryptominer on systems with port 5900 exposed. The incident underscores the need for robust access‑control evidence and continuous patch‑management to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 17, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
helpnetsecurity.com

Active Exploitation of macOS Screen Sharing Vulnerability (CVE‑2026‑65400) Enables Unauthorized Root Access and Cryptomining

What It Is – A flaw in macOS Screen Sharing (CVE‑2026‑65400) lets an attacker authenticate without valid credentials, obtain root privileges, and install a Monero cryptominer. Apple released patches for macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1, but threat actors began exploiting the vulnerability within days of the advisory.

Exploitability – Public proof‑of‑concept code is available; multiple active attacks have been reported on systems with port 5900 exposed to the Internet. CVSS not disclosed, but the ability to gain root access classifies the risk as High.

Affected Products – Apple macOS Sequoia, macOS Sonoma, macOS Tahoe (all versions prior to the listed patches).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Control criteria require documented mechanisms that prevent unauthorized logins; a bypass of Screen Sharing directly violates the CC6.1 and CC6.2 controls.
  • Continuous evidence of patch management and network segmentation is essential to demonstrate due diligence during a SOC 2 audit.
  • Enterprise buyers increasingly demand proof that remote‑access services are hardened and monitored, making this exploit a red flag for third‑party risk assessments.

Recommended Actions

  • Verify that all macOS endpoints are running the latest patches (Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1) or later.
  • Immediately disable Screen Sharing on systems that cannot be patched, using System Settings → General → Sharing.
  • Block inbound TCP 5900 at the perimeter firewall and enforce network‑level segmentation for remote‑desktop services.
  • Deploy endpoint detection and response (EDR) rules to alert on unexpected root‑level processes and cryptomining binaries.
  • Log all Screen Sharing sessions and correlate with identity‑provider logs to prove that only authorized users accessed the service.

Source: Help Net Security – Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer

📰 Original Source
https://www.helpnetsecurity.com/2026/08/17/apple-macos-screen-sharing-flaw/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →