arstechnica.com Active Exploitation of macOS Vulnerability CVE-2026-65400
Article Content
- •CVE-2026-65400 is actively exploited, allowing remote code execution on macOS.
- •Systems with port 5900 exposed are particularly vulnerable to this attack.
- •A patch was released by Apple last week, but exploitation is confirmed in the wild.
A high-severity macOS vulnerability, tracked as CVE-2026-65400, is currently under active exploitation, allowing attackers to execute malicious code. The Netherlands National Cyber Security Centrum reported that systems with port 5900 exposed to the Internet have been compromised, with root access gained and Monero crypto miners installed. The vulnerability, which affects macOS Tahoe, Sequoia, and Sonoma, has a CVSS score of 7.1, indicating a high severity level. It is caused by a flaw in the screen sharing capability's state management. Apple issued a patch for this vulnerability last week, but the exploit was publicly detailed at the Black Hat security conference. Apple has stated that the vulnerability may allow unauthorized access without credentials, though the exact nature of the exploitation remains unclear. Security firm Bynario is credited with reporting the vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-65400 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which macOS versions are affected?
Is there a patch available?
What should I do if my system is affected?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…