Back to blog
CVEAuthenticationmacOScloud

macOS Screen Sharing CVE-2026-65400: Bypassing Authentication to Mine Cryptocurrency

Published on 2026-08-185 min readCleanIssue

> TL;DR: CVE-2026-65400 (CVSS 9.8) is an improper authentication vulnerability in macOS Screen Sharing that lets a network-based attacker authenticate to the service without valid credentials. The flaw was exploited to deploy Monero cryptocurrency miners before CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on August 18, 2026, with a patch deadline of August 21 for U.S. federal agencies.

The flaw in brief

macOS Screen Sharing is designed to allow authenticated remote access to a machine. A flaw in the credential validation logic allows an attacker to bypass that check and gain access without holding a valid account on the target machine — a particularly dangerous combination for a service specifically designed to provide remote control.

Why cryptomining is often the first signal, not the worst-case scenario

The exploitation observed so far deploys Monero miners — a relatively quiet, low-impact use compared to ransomware or data theft. But this is often the pattern with newly discovered remote-access flaws: the first exploiters are opportunistic and looking for quick profit (mining), while more sophisticated actors analyze the flaw for more targeted uses (data theft, lateral movement, ransomware). Finding a Monero miner on a machine is a warning sign that unauthorized access exists — not proof that the impact is limited to mining.

What to do

  • Apply Apple's fix as soon as it's available on every macOS machine exposing Screen Sharing.
  • Disable Screen Sharing on machines that don't need it, especially those reachable from untrusted networks.
  • Hunt for unknown mining processes (abnormal CPU/GPU usage, connections to mining pools) on your macOS fleet, a potential sign of an already ongoing compromise.
  • Treat any cryptomining detection as a full security incident, not just a performance nuisance — audit the full extent of access the attacker obtained.
  • What CleanIssue checks for

    During a fleet audit, we check the exposure of remote-access services (Screen Sharing, VNC, RDP) and the robustness of their authentication, in addition to standard web and API surfaces.

    Key takeaways

  • An authentication flaw on a remote-access service deserves the same urgency as an RCE, even if the initial exploitation seems minor (cryptomining).
  • Disable any remote-access service that isn't actively needed — the safest attack surface is one that doesn't exist.
  • A cryptomining signal should trigger a full investigation of what access the attacker obtained, not just killing the malicious process.
  • Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Sources

    Related services

    If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit