CVE-2026-65400 grants root without credentials via Screen Sharing and installs Monero miners
Patched by Apple on August 6, 2026, the Screen Sharing authentication bypass (CVE-2026-65400) is being actively exploited on Macs exposed on port 5900: attackers gain root and deploy Monero miners. Disable Screen Sharing or apply the update, and never expose port 5900 to the internet.