The Netherlands’ National Cyber Security Centre (NCSC) is warning Mac users that hackers are actively exploiting a recently patched vulnerability in macOS Screen Sharing after public exploit code became available.
The security issue, tracked as CVE-2026-65400, affects macOS Screen Sharing, Apple’s built-in remote desktop feature that allows users to control a Mac remotely over a network. The service uses the VNC protocol and operates through TCP port 5900.
Apple fixed the vulnerability on August 6 with security updates for supported versions of macOS. The flaw can allow an attacker on the network to bypass authentication and gain access to a vulnerable Mac without having valid credentials.
Once access is obtained, an attacker could remotely open applications, access files, change security settings and carry out other actions on the system.
The NCSC has now updated its original advisory after receiving a report that the vulnerability is being exploited in real-world attacks against systems where port 5900 was exposed directly to the internet.
According to the Dutch agency, attackers gained root access on multiple affected systems and installed Monero cryptocurrency miners. The agency said it had received reports of active exploitation on several systems with the Screen Sharing service accessible from the public internet.
Apple has addressed CVE-2026-65400 in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. The updates improve state management mechanisms to enforce proper credential validation and prevent unauthorized authentication attempts.
Mac users who cannot immediately install the updates can also reduce their exposure by disabling Screen Sharing if they do not need the feature. The option is available under System Settings → General → Sharing → Screen Sharing.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The NCSC has not disclosed when the attacks began, how many systems have been compromised, whether the vulnerability is being used for purposes beyond cryptocurrency mining, or whether other types of malicious activity have been observed.





