CISA rescored the Screen Sharing flaw to 9.8 critical on August 14, eight days after Apple shipped a patch, once Dutch researchers confirmed active abuse.
If your Mac has Screen Sharing turned on and exposed to the internet, an attacker on the same network can take full control of the machine and run a Monero miner in the background. Screen Sharing is Apple's built-in remote-access feature, normally used for IT support or working from a second Mac.
CISA rescored the bug from 7.1 to 9.8 critical on August 14, eight days after Apple shipped an out-of-band patch covering macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The Dutch NCSC first warned of the flaw on August 7 and updated the advisory on August 12 to confirm active in-the-wild abuse, with attackers gaining full system control in every reported case.
Tracked as CVE-2026-65400, the flaw lets an unauthenticated visitor authenticate as any user on Macs listening on port 5900, the standard remote-desktop port. A public proof-of-concept now circulates on full-disclosure mailing lists. The bug is not yet in CISA's Known Exploited Vulnerabilities catalog, even with a public exploit and confirmed abuse.
If your Mac runs Tahoe, Sequoia, or Sonoma, install the August 6 update tonight. If you cannot update immediately, open System Settings, choose General > Sharing, and turn Screen Sharing off, or close port 5900 at the network edge.