NewsCryptoCISA Raises macOS Screen Sharing Flaw to Critical 9.8 After Monero Mining Attacks on Rented Macs

CISA Raises macOS Screen Sharing Flaw to Critical 9.8 After Monero Mining Attacks on Rented Macs

Author: Cryptopolitan·

Key Takeaways

  • CISA raised the macOS Screen Sharing vulnerability CVE-2026-65400 from 7.1 to 9.8 after reports of active exploitation.
  • Apple released fixes on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
  • Researchers said the flaw allows attackers to bypass authentication before password verification and gain root access on exposed Macs.
  • The Dutch National Cyber Security Centre said attackers used the default Screen Sharing port 5900 and deployed a Monero miner on compromised systems.
  • Huntress reported finding tens of thousands of potentially vulnerable internet-exposed hosts, many linked to rented bare-metal Macs.
CISA Raises macOS Screen Sharing Flaw to Critical 9.8 After Monero Mining Attacks on Rented Macs

CISA raised the severity score for a macOS Screen Sharing vulnerability to a critical 9.8 out of 10 on Friday, after Dutch investigators reported attackers gaining root control of internet-exposed Macs and quietly loading Monero mining software.

From 7.1 to 9.8 in a week

When Apple shipped its fix, CISA listed the bug, tracked as CVE-2026-65400, at 7.1 in the National Vulnerability Database. The agency has since raised it to 9.8, near the top of the CVSS scale.

The Netherlands' National Cyber Security Centre (NCSC) took a similar path. An August 12 update to its initial advisory stated that public proof-of-concept code was in circulation and that active abuse had been confirmed.

As of Friday, the flaw had not been added to the federal catalog of known attacked vulnerabilities maintained by the Cybersecurity and Infrastructure Security Agency. Apple's own CVE record with the Dutch agency still carried the older 7.1 rating.

An authentication failure before the password check

The vulnerability lies in how Screen Sharing handles authentication. Security firm Huntress traced it to a flaw in the service's use of Secure Remote Password, the protocol used to verify a user's identity before granting access.

Huntress says the practical effect is that the Mac treats the outsider as already signed in. The failure occurs prior to any password verification, and resetting or deleting Screen Sharing passwords does not shut the door.

"Anybody who leverages Apple's Screen Sharing functionality on any supported macOS version needs to apply the most recent security updates immediately," Huntress researcher Ryan Dowd wrote.

Apple delivered that fix on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

Tens of thousands of rented Macs in range

The NCSC found that victim machines were totally compromised. In each case examined by the researchers, the attacker accessed the system via port 5900, the default Screen Sharing port that remained exposed to the internet, then escalated to root privileges and deployed a Monero (XMR) cryptocurrency miner. The Dutch agency gave no number of systems affected and did not name a suspect.

Screen Sharing is disabled by default. It is, however, a standard tool for working with "bare-metal" Macs — physical Apple hardware rented and run inside remote data centers, where much of the exposure is concentrated. Using the internet-scanning tool Censys, Dowd said he found "tens of thousands of potentially vulnerable hosts." Many, according to Huntress, are machines rented by the hour from hosting services. For operators of those environments, the issue goes beyond a single misconfiguration: any exposed management service can turn a rented machine into an easy target for unauthorized access and hidden resource use.

Monero's long history with cryptojacking

Cryptopolitan previously reported on the Reaper malware that hijacks Script Editor to drain wallets, and on fake macOS troubleshooting posts that lead victims to paste malicious Terminal commands.

Cryptojacking — stealing computing power to turn into coins — has long been a Monero activity. Unlike coins that require specialist rigs, Monero can be mined on normal CPUs, and its transactions are private by design.

The return per hijacked Mac is small. At Monday's price, the roughly 432 XMR minted per day by the Monero network, valued at about $179,000, is distributed across all miners. XMR was trading at $413.47 on Monday, up about 0.9% over 24 hours. That limited payout helps explain why attackers tend to scale such campaigns across many exposed systems rather than rely on a single host.