Dutch NCSC warns exploited macOS flaw CVE-2026-65400 enables Monero mining

A macOS Screen Sharing vulnerability tracked as CVE-2026-65400 has been actively exploited to compromise internet-exposed Macs, obtain root access and install Monero mining software, prompting a warning from the Netherlands National Cyber Security Centrum. Dutch officials said multiple systems exposing port 5900 were abused and urged users to update to Apple's fixes in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9, after the risk shifted from a theoretical flaw to confirmed exploitation. Apple said the bug stemmed from improper state management that let a network attacker bypass Screen Sharing authentication without valid credentials, effectively enabling control comparable to physical access to the machine. Security researcher Calif published a proof-of-concept on Aug. 8 showing the issue could be exploited when Screen Sharing was enabled and without knowing an account password. Huntress said the weakness affects the Secure Remote Password process used by Screen Sharing and can make a Mac treat an unauthenticated connection as authenticated, while researcher Ryan Dowd said tens of thousands of potentially vulnerable hosts were visible through Censys. The U.S. Cybersecurity and Infrastructure Security Agency initially rated the flaw 7.1 out of 10 before later raising it to 9.8. Security guidance has centered on patching affected Macs, disabling Screen Sharing when not needed, and keeping port 5900 closed to the public internet or restricted to safer access methods such as VPN-based remote support.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.