HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical macOS Screen Sharing Auth Bypass (CVE‑2026‑65400) Enables Remote Root Access and Monero Mining

A pre‑authentication flaw in macOS Screen Sharing (CVE‑2026‑65400) is being actively exploited to gain root privileges and install Monero miners. The vulnerability underscores the need for robust SOC 2 access‑control monitoring and rapid patch management.

LiveThreat™ Intelligence · 📅 August 15, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

macOS Screen Sharing Authentication Flaw (CVE‑2026‑65400) Enables Remote Root Access and Monero Mining

What It Is — A pre‑authentication vulnerability in macOS’s built‑in Screen Sharing service allows an attacker on the network to authenticate without valid credentials, gaining full root privileges. Apple released patches in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9.

Exploitability — Actively exploited in the wild within two weeks of disclosure; attackers scan for systems with TCP 5900 exposed and install Monero miners. CVSS 9.8 (Critical).

Affected Products — Apple macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9 (any version prior to these patches).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Controls – The flaw bypasses authentication, directly violating the Logical Access (CC6.1) and System Operations (CC7.1) criteria that require verified identity before privileged actions.
  • Continuous Monitoring – Detecting unauthorized remote sessions and unexpected cryptomining processes is essential evidence for the Monitoring (CC8.1) control set.
  • Audit Trail Integrity – Unpatched endpoints can create gaps in log completeness, jeopardizing the System Monitoring and Change Management controls auditors scrutinize during SOC 2 examinations.

Recommended Actions

  • Deploy Apple’s security updates (macOS Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9) across all managed Macs.
  • Disable Screen Sharing on devices that do not require remote desktop, or restrict it to trusted internal subnets via firewall rules.
  • Enforce MFA for any remote access solution and ensure session logging is enabled and retained per SOC 2 requirements.
  • Implement continuous endpoint monitoring to flag unexpected processes (e.g., cryptominers) and anomalous remote logins.
  • Document remediation steps and retain patch‑deployment evidence for audit readiness.

Source: Security Affairs – macOS Screen Sharing Flaw Exploited to Deploy Monero Miners

📰 Original Source
https://securityaffairs.com/197234/uncategorized/macos-screen-sharing-flaw-exploited-to-deploy-monero-miners.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →