The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting an authentication bypass vulnerability in macOS Screen Sharing after public exploit code emerged. The agency says it has received a report of the flaw being abused in the wild against systems that expose port 5900 to the internet.
The vulnerability, tracked as CVE-2026-65400, affects macOS Screen Sharing, Apple’s built-in remote desktop feature that uses the VNC protocol over TCP port 5900. The flaw allows a network-based attacker to gain access to a Mac without valid credentials, letting them remotely open applications, access files, change security settings, and carry out other actions normally reserved for an authenticated user.
Apple patched the issue on August 6 in macOS Tahoe 26.6.1 and earlier supported releases. According to the NCSC’s updated advisory, the fixes improve state management mechanisms to properly enforce credential validation and block rogue authentication attempts.
Root access and Monero mining
In the confirmed exploitation cases reported to the NCSC, attackers obtained root access to affected systems and deployed a Monero cryptocurrency miner. The agency stated that on every system it reviewed where port 5900 was reachable from the internet, root had been compromised and a Monero miner installed.
The NCSC has not disclosed further details about the campaign, including when the attacks began, whether the intrusions extend beyond cryptomining, or how many systems have been affected so far.
Recommended actions
Apple has released fixes addressing CVE-2026-65400 in the following updates:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
Organizations and users should apply these updates as soon as possible. Where immediate patching isn’t feasible, Screen Sharing can be disabled through System Settings under General, Sharing, Screen Sharing. Administrators should also audit firewall rules to ensure port 5900 is not exposed directly to the internet, since that exposure appears to be a prerequisite for the observed attacks.
