What happened
Apple released macOS Tahoe 26.6.1 on 6 August 2026 with a fix for CVE-2026-65400. Apple describes CVE-2026-65400 as an authentication issue that could let a network attacker authenticate to Screen Sharing without valid credentials. Apple’s fixed release names cited by the NCSC are macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. The vendor described improved state management as the corrective change but did not characterise the original disclosure as known exploitation.
The NCSC alert, first published on 7 August 2026, records an update at 10:44 on 13 August 2026 that reports active exploitation. Observed exploitation required Screen Sharing to be enabled and TCP port 5900 to be reachable from the internet. In the incidents reported to the NCSC, attackers obtained root access and installed cryptomining software. This materially changes the enterprise response from expedited patching to identifying potentially compromised systems and preserving evidence before remediation removes useful artefacts.
Security.NL reported on 12 August 2026 that proof-of-concept code was public and that the NCSC had received reports involving multiple exposed systems. The NCSC alert did not publish attacker IP addresses, domains, file hashes, filenames or persistence paths. Defenders therefore have a precise exposure test but no payload-specific hunt package from the cited primary alert. Attribution posture: The NCSC did not identify an actor behind the observed exploitation. The number, ownership and geography of affected systems remain unpublished.
Why this matters now
The exposure boundary is narrower than the installed macOS population but more dangerous than an ordinary endpoint patch gap. A vulnerable Mac must have Screen Sharing enabled and TCP port 5900 reachable from the internet for the observed path, so generic operating-system compliance percentages cannot answer whether the organisation is exposed. Security leaders need a joined view of software release, service state, firewall path, ownership and business criticality.
Root access changes the closure standard. Installing the fixed release prevents the documented authentication bypass, but it does not establish that a previously exposed host remained clean. A root-level intruder could alter local accounts, remote-access settings, launch services or security controls. The reported cryptominer establishes operational exploitation, not the maximum possible consequence, so previously reachable systems require incident review even when performance symptoms are absent.
The decision for security leaders
Assign a single exposure owner to combine endpoint inventory, Screen Sharing configuration and network-path evidence. Separate teams returning separate spreadsheets will not prove whether an exploitable combination exists.
Require two closure tracks. Endpoint engineering must install and validate a fixed release; incident response must determine whether any previously reachable host shows unauthorised root access, new accounts, persistence, cryptomining or security-control changes.
Do not accept disabling Screen Sharing alone as compromise closure. Configuration containment reduces future reachability, but previously exposed systems need evidence covering the period when the vulnerable service was reachable.
Treat prior internet reachability as incident-response scope, not merely a configuration-management task, because containment does not establish historical compromise status.
Evidence of closure
- A signed exposure report shows no unapproved Mac has Screen Sharing reachable from the internet.
- Device records confirm every in-scope Mac runs Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9 or later.
- Incident records document clean forensic findings or an approved containment disposition for every previously exposed Mac.
- Firewall validation proves TCP port 5900 is restricted to approved management paths.
The Security.io assessment
The exploitation finding is high confidence because it comes from a national cyber authority and is consistent with Apple’s confirmed authentication flaw. The affected population is constrained by service state and network reachability, which makes rapid, accurate inventory more valuable than broad severity-based messaging.
The NCSC alert did not publish attacker IP addresses, domains, file hashes, filenames or persistence paths. Until those artefacts emerge, detection must emphasise exposure history, unexpected root activity, remote logins, new persistence and unexplained compute utilisation rather than a narrow indicator match. Attribution posture: The NCSC did not identify an actor behind the observed exploitation.
The reported payload was cryptomining software, but root access is the decision-driving fact. Security.io does not infer data theft, credential theft or destructive activity from the available evidence. Our assessment changes if authoritative sources document those outcomes or show exploitation against systems that were not internet-reachable on TCP port 5900.
Questions for the morning meeting
- Can the endpoint team prove which Macs expose Screen Sharing beyond trusted management networks?
- Does the incident process treat patch installation and compromise assessment as separate closure requirements?
- Who can isolate an exposed executive, developer or production Mac without waiting for a standard change window?