< Back to all clusters
[TECHNOLOGY] · Netherlands, United States · 14 sources

started · updated

macOS Screen Sharing vulnerability exploited for Monero mining

A critical vulnerability in Apple’s macOS Screen Sharing feature, tracked as CVE-2026-65400, is being actively exploited by attackers to gain root access to internet-exposed Mac computers. The Netherlands National Cyber Security Centre (NCSC) reported that attackers are using the flaw to install Monero (XMR) cryptomining software, hijacking the computing power of compromised machines.

The vulnerability is an authentication-bypass flaw that allows remote attackers to connect to the Screen Sharing service via port 5900 without valid credentials. Because the exploit occurs prior to authentication, simply changing or removing Screen Sharing passwords does not protect vulnerable systems. Security firm Huntress identified tens of thousands of potentially vulnerable hosts, including many rented Macs used by hosting providers.

In response to the active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) upgraded the vulnerability’s severity score from 7.1 to a critical 9.8 out of 10. Apple released emergency security updates on August 6 to address the issue. The patches are available for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Experts recommend that users immediately update their systems and disable Screen Sharing if it is not actively required.

Entities

Apple · CISA · Huntress · Monero · NCSC · NCSC-NL · macOS

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

Sources

about 12 hours ago
about 3 hours ago