CRITICAL: Apple macOS Screen Sharing CVE-2026-65400 Exploited for Root Access
Apple shipped an out-of-band fix on August 6 for a pre authentication bypass in macOS Screen Sharing, and CISA rescored it to CVSS 9.8 after attackers began using it to take root and install Monero miners. Macs with port 5900 reachable are being compromised with no credentials required. The fix is in Sonoma 14.8.9, Sequoia 15.7.9, and Tahoe 26.6.1.