A Pre-Auth Path From Port 5900 to Root
The flaw lives in screensharingd, the macOS process that answers VNC connections on TCP port 5900, and it lets a network attacker complete authentication without supplying a password or any other credential. Once authentication is bypassed, that same pre-auth path lets the attacker write files as root, which is enough to install code that runs with full system privileges - the textbook definition of remote code execution.
Tanium's technical writeup breaks down how thin the barrier actually was: a Mac with Screen Sharing turned on and port 5900 reachable from the network had, in effect, no authentication step standing between an attacker and root. No credentials required, and root at the end of it, is why CISA treats this as one of the more severe flaws in a normal patch cycle rather than a routine bug that happened to get an unusually strong writeup.
August 6: Three Patches Ship, One Timeline Begins
Apple shipped the fix for this flaw on August 6, 2026, releasing it at the same time across three supported operating system lines: macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. A same-day fix across three active releases is what a fast, well-executed patch looks like, and it is the detail most short summaries of this story stop at.
| Milestone | Date |
|---|---|
| Apple patch released (Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9) | August 6, 2026 |
| CVSS score | 9.8 out of 10 (rescored from 7.1) |
| NCSC-NL reports active exploitation | Around August 12, 2026 |
| Added to CISA KEV catalog | August 18, 2026 |
| Federal remediation deadline | August 21, 2026 (passed) |
A patch existing since August 6 is a claim about what Apple shipped, not a claim about what is running on any given Mac today. A Mac that has not rebooted into the new build, a Mac managed outside a standard update policy, or a Mac whose owner postponed the update notification is exactly as exposed on the date this article published as it was on August 5.
August 12: NCSC-NL Finds Every Case Ends the Same Way
NCSC-NL, the Dutch national cyber security centre, reported active exploitation of the flaw around August 12, 2026, less than a week after Apple's patch had shipped. In every case NCSC-NL observed, the intrusion ended the same way, with a Monero cryptocurrency miner installed on the compromised Mac.
Malwarebytes' blog pointed to that outcome as the tell for what this vulnerability is actually being used for right now, not data theft or ransomware, but quiet, ongoing compute theft that a miner is built to run for as long as it goes unnoticed. A cryptominer is also one of the easier compromises to miss, since it does not lock a screen or demand a ransom, it just runs in the background and consumes CPU cycles, which is exactly why an unmonitored Mac on port 5900 can stay compromised for a long time without anyone noticing.
August 14 to August 18: A Rescore, Then a Six-Day Wait for KEV
CISA rescored the vulnerability's severity from 7.1 to 9.8 out of 10 on August 14, 2026, two days after NCSC-NL's report of active exploitation became public. Tom's Hardware's coverage of the rescoring noted that the jump reflected how easily the flaw could be triggered over the network, once real-world exploitation confirmed what the original score had underestimated.
CISA did not add the flaw to its Known Exploited Vulnerabilities catalog until August 18, 2026, four days after the rescore and six days after NCSC-NL's report of active exploitation. Help Net Security's August 17 coverage had already flagged the flaw as urgent before the KEV listing caught up, and the federal remediation deadline that came with the listing, August 21, 2026, had already passed by the time this article was published.
The Patch Date Is Not the Deployment Date
A patch shipped on August 6 is a fact about what Apple made available, not a fact about what is installed on any specific Mac today. The gap that matters is not between disclosure and patch, which Apple closed quickly, but between patch and deployment, between a fix existing and a fix actually reaching every Mac that has Screen Sharing turned on and port 5900 reachable from a network.
CISA's own six-day gap between NCSC-NL's report and the KEV listing makes the same point from the institutional side: even a 9.8-severity flaw with confirmed active exploitation did not move instantly through the system built specifically to flag it. If a formal tracking process can lag active exploitation by nearly a week, an individual Mac fleet with no dedicated watch on port 5900 can lag by far longer. Checking that the patch actually installed, and turning off Screen Sharing wherever it does not need to be on, is the only way to close that gap.
Read next: Your April Windows VPN Patch Is Being Exploited | A Single Photo Could Have Hijacked Your iPhone



