Skip to content
Active Exploitation of macOS Vulnerability CVE-2026-65400

Active Exploitation of macOS Vulnerability CVE-2026-65400

First seen 5 Oct 2026, 11:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 12:27 UTC
  • •CVE-2026-65400 is actively exploited, allowing remote code execution on macOS.
  • •Systems with port 5900 exposed are particularly vulnerable to this attack.
  • •A patch was released by Apple last week, but exploitation is confirmed in the wild.

A high-severity macOS vulnerability, tracked as CVE-2026-65400, is currently under active exploitation, allowing attackers to execute malicious code. The Netherlands National Cyber Security Centrum reported that systems with port 5900 exposed to the Internet have been compromised, with root access gained and Monero crypto miners installed. The vulnerability, which affects macOS Tahoe, Sequoia, and Sonoma, has a CVSS score of 7.1, indicating a high severity level. It is caused by a flaw in the screen sharing capability's state management. Apple issued a patch for this vulnerability last week, but the exploit was publicly detailed at the Black Hat security conference. Apple has stated that the vulnerability may allow unauthorized access without credentials, though the exact nature of the exploitation remains unclear. Security firm Bynario is credited with reporting the vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-06
CVE-2026-65400 published
A high-severity macOS vulnerability was disclosed, allowing remote code execution.
Ars Technica
2026-08-18
CVE-2026-65400 added to CISA KEV
CISA confirmed active exploitation of the vulnerability in the wild.
Ars Technica
2026-09-29
Patch released by Apple
Apple issued a patch for macOS Tahoe, Sequoia, and Sonoma addressing CVE-2026-65400.
Stratechery

More articles in this cluster (3)

Following this threat?

Track CVE-2026-65400 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which macOS versions are affected?
macOS Tahoe, Sequoia, and Sonoma are affected by CVE-2026-65400.
Is there a patch available?
Yes, Apple released a patch for the vulnerability on September 29, 2026.
What should I do if my system is affected?
Apply the patch immediately and ensure that port 5900 is not exposed to the Internet.