Your Macs Need Patches Too. Most Firms Aren't Doing It.
A macOS vulnerability is being actively exploited right now. If your firm doesn't patch Macs the same way it patches Windows, you have a gap nobody is watching.
On August 14, the Netherlands’ cybersecurity agency reported that attackers are actively exploiting a macOS Screen Sharing vulnerability (CVE-2026-65400) to gain root access to unpatched systems. The attackers are accessing machines remotely without valid credentials, then deploying cryptocurrency miners. Apple patched it on August 6. If your Macs haven’t been updated since then, they’re vulnerable.
This isn’t a theoretical risk or a proof-of-concept sitting on a researcher’s GitHub page. It’s being used right now against machines that have port 5900 exposed (the default for Screen Sharing).
But the bigger issue isn’t this one vulnerability. It’s that most firms have no process for macOS patching at all.
The patching gap
At firms we work with, the Windows machines are patched monthly. There’s a schedule, there’s a process, there’s accountability. Updates get tested, approved, and deployed. If a machine misses a patch cycle, someone notices.
The Macs? “They update themselves.” Or more accurately, nobody is checking whether they do.
macOS does have automatic updates, but the default behavior is to download updates and notify the user. The user then has to agree to restart. And users are remarkably good at clicking “Remind me tomorrow” for weeks on end, especially when they’re in the middle of something, which at a law firm is always.
Apple released security patches on August 6. As of today, any Mac still running macOS Tahoe below 26.6.1, or Sequoia below 15.7.9, or Sonoma below 14.8.9, is vulnerable to a flaw that is being actively exploited. How many Macs at your firm are still on the old version? Do you know?
Why firms assume Macs are fine
There’s a persistent belief that Macs don’t get malware, don’t need antivirus, and don’t need the same patching discipline as Windows. This was partially true in 2010 when macOS market share was low enough that attackers didn’t bother. It hasn’t been true for years.
In 2026 alone:
- CVE-2026-65400: Screen Sharing authentication bypass, actively exploited (August)
- CrashStealer: macOS info-stealing malware disguised as Apple’s crash reporting tool (July)
- macOS ClickFix: a campaign silently mounting DMG files to push infostealers (June)
- The DarkSword exploit kit targeting iOS devices, requiring multiple emergency patches from Apple (April)
Apple released security updates in January, March, April, May, June, July, and August of this year. Each one addressed vulnerabilities that could compromise your data. If your Macs aren’t being updated on a similar cadence to your Windows machines, you have a gap, and unlike the Windows gap, nobody at your firm is probably tracking it.
What “managed” should mean for Macs
When we say a Windows machine is managed, we mean patches are deployed on a schedule, compliance is reported, and failures are flagged. The same standard should apply to Macs, but in practice it often doesn’t because the tools and processes were built for Windows first and macOS was an afterthought.
What macOS patch management should look like at a professional services firm:
Patches should be deployed within a defined window (typically 14 days for standard updates, faster for actively exploited vulnerabilities). Someone should be able to tell you which Macs are current and which are behind. If a machine hasn’t updated in 30+ days, that should trigger an action, not go unnoticed until the next hardware refresh.
For firms on Microsoft Intune (part of Business Premium), macOS devices can be enrolled and managed alongside Windows machines. Patch compliance can be monitored, update policies can be enforced, and non-compliant devices can be flagged or blocked from accessing company resources through Conditional Access.
For firms without Intune, there are other approaches (RMM tools, Apple Business Manager, Munki), but the point is the same: Macs need a deliberate patching process. “Automatic updates” with no verification is not a process.
What to check this week
If your firm has Macs (even just a few), here’s what to verify:
Check what macOS version each machine is running. Go to Apple menu > About This Mac. If it’s below macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9, it’s missing the patch for a vulnerability that’s being actively exploited right now.
Check whether Screen Sharing is enabled. System Settings > General > Sharing > Screen Sharing. If it’s on and you don’t know why, turn it off. If it’s on because someone uses it for remote support, confirm it’s not exposed to the internet (it shouldn’t be accessible from outside your network).
Ask your IT provider how Mac patches are tracked. If the answer is “we assume they auto-update,” that’s not a tracking process. If the answer is “we can show you a compliance report,” that’s better. If your IT provider doesn’t manage your Macs at all, you have unmonitored endpoints on your network.
Check your cyber insurance application. Many applications ask about vulnerability management and patching cadence. If you attested that all endpoints are patched within X days and your Macs are running three months behind because nobody checks them, that’s the same attestation gap we’ve discussed in previous posts.
The firms that run into trouble aren’t the ones with zero security. They’re the ones with good security on 80% of their devices and no visibility into the other 20%. The Macs are usually in that 20%.
If you’re not sure whether your Macs are being patched on the same schedule as your Windows machines, that’s something we can help you sort out.

