Dutch cybersecurity authorities are warning that a high-severity macOS vulnerability is being actively exploited to gain unauthorized access and execute malicious code on vulnerable Macs.
“The NCSC has received notification that active exploitation of this vulnerability has been observed on multiple systems that have access to port 5900 from the internet,” the Dutch National Cyber Security Centre warned earlier this week. “In all of these cases, root was accessed and a Monero crypto miner was deployed on the affected systems.”
Is macOS Screen Sharing enabled on your Mac?
The vulnerability, tracked as CVE-2026-65400, affects the macOS Screen Sharing feature and was patched by Apple last week in updates for macOS Tahoe, macOS Sequoia, and macOS Sonoma.
CVE-2026-65400 has a severity score of 7.1 out of 10. The flaw is linked to a state-management bug that improperly handles previous events, user actions, variables, and other system information. macOS Screen Sharing allows a remote user to view a Mac’s display and control its keyboard and mouse while the computer is powered on.
A video of the exploit in action is available online. Technical details about CVE-2026-65400 were disclosed at last week’s Black Hat security conference.
Apple said the vulnerability “could” allow an unauthenticated attacker to access a Mac. Although the company used cautious language in its advisory, security researchers and Dutch authorities have confirmed that attacks are occurring in the wild.
Mac users should install the latest available macOS security updates and check whether Screen Sharing is enabled. Systems with port 5900 exposed directly to the internet face increased risk and should be secured immediately.
Source: arstechnica.com


