Skip to content
operating-system

CVE-2026-65400

Description

CVE-2026-65400 describes an improper authentication vulnerability in macOS that abuses the daemon behind screen sharing, screensharingd, a VNC-based remote desktop service operating on TCP/5900.

Impact

Exploitation of this vulnerability allows attackers to initiate a screen-sharing session to access files and perform remote code execution as root. Delivery and execution of XMRig cryptominers have been a common outcome when this vulnerability has been exploited in the wild.

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.