Skip to content

Security Advisory: Critical macOS Screen Sharing Vulnerability (CVE-2026-65400)

Security Advisory: Critical macOS Screen Sharing Vulnerability (CVE-2026-65400)

Apple has released security updates for a critical vulnerability in the macOS Screen Sharing service. This page explains what the issue is, how to tell whether your Mac is affected, and the steps we recommend you take. If you host a Mac, please read this carefully since this vulnerability is actively being exploited.

What is the vulnerability?

CVE-2026-65400 is a remote code execution (RCE) vulnerability in the macOS Screen Sharing service, which listens on TCP port 5900. It allows an attacker to run code on a vulnerable Mac and can be used to fully compromise the system. No valid username or password is required for the attack to succeed, so standard account hardening does not protect against it.

For technical details, see the references at the bottom of this page.

Am I affected?

Your hosted Mac is at risk if all of the following are true:

  • It is running a version of macOS that has not been updated to one of the patched versions listed below, and
  • The Screen Sharing service (port 5900) is reachable from the internet, and
  • There is no firewall (software or hardware) in front of the Mac restricting access to port 5900.

If your Mac is behind a firewall that blocks inbound access to port 5900, or you have disabled Screen Sharing, or you have already updated to a patched version of macOS, you are protected from this specific issue, but you should still check to make sure there was no compromise before updating macOS. Updating a compromised Mac will not clean up the compromise.

Which macOS versions are patched?

Apple has fixed the vulnerability in the following releases. Update to the version that matches your macOS line:

macOS Major VersionPatched version
macOS Tahoe (26)26.6.1
macOS Sequoia (15)15.7.9
macOS Sonoma (14)14.8.9

Older, unsupported versions of macOS do not receive this fix. If you are running an older release, you should upgrade to a supported, patched version.

What does Mac Mini Vault manage, and what do I manage?

Mac Mini Vault provides dedicated, unmanaged Apple hardware. You control the operating system, the software, the accounts, and the firewall configuration on your Mac. We do not manage, patch, or configure the macOS installation on customer machines, and we do not have visibility into what runs inside them.

Because of this, we cannot apply this update on your behalf. Keeping macOS current and running a firewall is the customer’s responsibility, and it is something we always recommend as a baseline hardening step for any internet-connected host.

How do I protect my Mac?

We recommend doing the following:

  1. Check for compromise. See next section for more information.
  2. Update macOS to the patched version for your macOS major version (26.6.1, 15.7.9, or 14.8.9). Go to System Settings, then General, then Software Update.
  3. Run a firewall. Either a managed dedicated firewall that we manage for you and that sits in front of your Mac(s), or a software firewall that you manage. As a rule, ports 5900 and 22 should never be open to the entire internet. Here’s a guide for setting up a software firewall: https://www.macminivault.com/installing-and-configuring-murus-firewall/

How can I tell if my Mac has already been compromised?

Attackers have been using this vulnerability to install cryptocurrency mining malware. Signs to look for on your Mac include:

  • Sustained very high CPU usage, often from a process disguised with a legitimate-looking Apple name (for example, sysmond) using several hundred percent CPU in Activity Monitor or “top” in Terminal.
  • Outbound network connections to cryptocurrency mining pools (for example, hostnames containing c3pool).
  • Unexpected files such as a hidden binary and log at /private/var/root/.config/.
  • Unexpected startup items in /Library/LaunchDaemons/, for example files named com.xmr.miner.plist or com.navi.*.plist.
  • Unusual firewall rules. A pf rule that blocks port 5900 from everyone except 127.0.0.1 (loopback) is not a normal hardening configuration and is a sign that an attacker may have locked the port behind themselves. Check pf firewall rules with sudo pfctl -sr

You can check running processes and CPU usage in the Activity Monitor app, or from Terminal with commands such as sudo launchctl list .

What should I do if I think my Mac is compromised?

Treat a confirmed compromise as a full breach of that machine. Here is what we recommend:

  1. Back up any important files to a remote computer so that you can ensure they stay safe, and can restore them later on.
  2. Do not simply delete the malware and continue. An attacker with root access can install additional hidden persistence (back doors), so cleaning in place is not reliable.
  3. Request a wipe/reinstall. Open a support ticket to request a reinstall of macOS on your Mac.
  4. Rotate (reset) any credentials, SSH keys, or secrets that were stored on or used to access that Mac.
  5. Contact our support team if you have any questions.

How do I get help?

If you have questions about this advisory or need help reprovisioning a Mac, contact Mac Mini Vault support. Please note that we can assist with the hardware and reprovisioning, but the macOS update and firewall configuration are performed by you on your machine.

References

All blog posts

Ready to rent a Dedicated Mac mini?