SUMMARYDutch cyber officials warned that a high-severity macOS flaw tracked as CVE-2026-65400 is being actively exploited on systems exposed through port 5900. The bug in Apple’s screen sharing feature can let attackers execute code and gain root access, and infected Macs have been found with Monero crypto miners installed. Apple patched the issue last week in macOS Tahoe, Sequoia, and Sonoma.

Isolated photo a 13 inch MacBook Pro Retina.
Getty Images
arstechnica.com
Isolated photo a 13 inch MacBook Pro Retina.

Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation.

“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”

Do you know if your screen sharing is on?

The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause.

Read full article