№227|08:43 PM ET
Independent reporting on technology, markets & policy
TechEchelon
№01 / Anchor·CYBERSECURITY

Hackers Exploit macOS Screen Sharing Flaw to Deploy Monero Miners as SAP Commerce Cloud RCE Bug Draws Active Attacks

Hackers are actively exploiting a macOS Screen Sharing authentication bypass to deploy Monero miners on internet-exposed systems, while a newly patched maximum-severity SAP Commerce Cloud remote code execution flaw is already drawing exploitation attempts just three days after its August Patch Day release.

TE
TechEchelon Staff
AUG 15, 2026 · 07:01 PM ET · 3 MIN READ
Photo by Sumudu Mohottige on Unsplash

Two critical vulnerabilities are drawing active exploitation this week — one targeting macOS systems with exposed remote desktop ports, the other a maximum-severity remote code execution flaw in SAP Commerce Cloud — underscoring the speed at which attackers move once patches become public.

The Netherlands' National Cyber Security Centre issued a warning, first reported by BleepingComputer, that hackers are actively exploiting CVE-2026-65400, an authentication bypass vulnerability in macOS Screen Sharing, Apple's built-in remote desktop feature, which operates via the VNC protocol over TCP port 5900.

Apple patched the flaw on August 6 in macOS Tahoe 26.6.1 and earlier releases. The vulnerability allows network-based attackers to gain access without valid credentials, enabling them to open applications remotely, access files, and alter security settings.

The Dutch agency said it received a report confirming exploitation in the wild on systems where port 5900 was exposed to the internet. "In all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed," the NCSC stated in its updated advisory.

The agency has not disclosed how many systems have been affected, when the attacks began, or whether exploitation extends beyond cryptocurrency mining.

Users are advised to upgrade to macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9, all of which address the flaw by improving state management mechanisms to enforce correct credential validation. Where updates cannot be applied immediately, Apple users can disable Screen Sharing through System Settings under General, then Sharing.

On the enterprise software front, a separate and equally urgent threat has emerged around SAP Commerce Cloud. Tracked as CVE-2026-58231 and carrying a CVSS score of 10.0, the flaw stems from an improper authorization weakness in the core Data Hub Adapter extension that allows unauthenticated attackers to execute arbitrary code in low-complexity attacks.

SAP patched the vulnerability on its August Patch Day, just three days before threat intelligence company Defused confirmed active exploitation attempts hitting its honeypots. "First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots — 3 days after patch day," Defused wrote in a Friday post. "This vulnerability has no public PoC and is not known to be exploited."

A SAP spokesperson told BleepingComputer that the company is aware of and investigating the issue. "A security note is published and available for SAP customers and partners and was released on SAP's August Patch Day. We recommend customers and partners patch their systems with immediate effect," the spokesperson said.

Internet security watchdog Shadowserver tracks over 4,200 IP addresses carrying a SAP Commerce Cloud fingerprint, with the majority located in Europe and North America. It remains unclear how many of those instances have already been secured against CVE-2026-58231 attacks.

SAP Commerce Cloud, formerly known as SAP Hybris, is a cloud-based e-commerce platform used by high-profile global brands and large retailers. SAP, a German multinational software corporation, serves 99 of the 100 largest companies worldwide and reported total revenues exceeding €36 billion in fiscal year 2025.

The SAP Commerce Cloud flaw is not the platform's first high-severity exposure. In April, attackers compromised multiple official SAP npm packages in a supply chain attack aimed at stealing developer credentials. Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency has added 14 SAP vulnerabilities to its Known Exploited Vulnerabilities catalog, including three tied to ransomware attacks.

The simultaneous exploitation of both vulnerabilities — one targeting personal computing environments, the other enterprise e-commerce infrastructure — reinforces a pattern security researchers have observed throughout 2026: the window between patch release and active attack continues to shrink, placing urgent pressure on organizations to prioritize patch deployment cycles.

Disclaimer

TE
━ ABOUT THE BYLINE
TechEchelon Staff

TechEchelon Staff bylines are produced collectively by the newsroom for short, breaking, and wire-style coverage. Longer-form reporting is published under the responsible reporter's name.

More from the Staff
● THE BRIEF · DAILY NEWSLETTER

Five stories every morning. Before the opening bell.

Written for readers who already know the basics — markets, AI, and the policy decisions that shape both.

Mon — Fri · 06:30 ET · Free

No spam · Unsubscribe anytime