macOS Screen Sharing CVE-2026-65400: Bypassing Authentication to Mine Cryptocurrency
> TL;DR: CVE-2026-65400 (CVSS 9.8) is an improper authentication vulnerability in macOS Screen Sharing that lets a network-based attacker authenticate to the service without valid credentials. The flaw was exploited to deploy Monero cryptocurrency miners before CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on August 18, 2026, with a patch deadline of August 21 for U.S. federal agencies.
The flaw in brief
macOS Screen Sharing is designed to allow authenticated remote access to a machine. A flaw in the credential validation logic allows an attacker to bypass that check and gain access without holding a valid account on the target machine — a particularly dangerous combination for a service specifically designed to provide remote control.
Why cryptomining is often the first signal, not the worst-case scenario
The exploitation observed so far deploys Monero miners — a relatively quiet, low-impact use compared to ransomware or data theft. But this is often the pattern with newly discovered remote-access flaws: the first exploiters are opportunistic and looking for quick profit (mining), while more sophisticated actors analyze the flaw for more targeted uses (data theft, lateral movement, ransomware). Finding a Monero miner on a machine is a warning sign that unauthorized access exists — not proof that the impact is limited to mining.
What to do
What CleanIssue checks for
During a fleet audit, we check the exposure of remote-access services (Screen Sharing, VNC, RDP) and the robustness of their authentication, in addition to standard web and API surfaces.
Key takeaways
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
VMware vCenter CVE-2026-59310: China-Linked APT Exploits Critical Flaw, France in the Top 5 Victims
CVE-2026-59310 (CVSS 9.8), a path traversal flaw in VMware vCenter, has been exploited by a suspected China-nexus actor to deploy backdoors and a Babuk-derived ransomware. 361 compromised IPs across 47 countries, including 25 in France.
SharePoint CVE-2026-58644: a critical RCE zero-day added to the CISA KEV catalog
A deserialization flaw (CVSS 9.8) in Microsoft SharePoint Server lets an attacker authenticated as Site Owner execute arbitrary code remotely. Actively exploited as a zero-day, added to the CISA KEV catalog on July 16, 2026 with a July 19 remediation deadline.
WordPress CVE-2026-8206: unauthenticated admin takeover via the Kirki plugin
The Kirki WordPress plugin (6.0.0 to 6.0.6) lets an unauthenticated attacker take over an administrator account via a broken password reset. CVSS 9.8, active exploitation, ~150,000 sites exposed. Fix: 6.0.7.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.