macOS screen-sharing flaw CVE-2026-65400 exploited to plant Monero miners

The Netherlands National Cyber Security Centrum (NCSC) warned this week that a high-severity macOS vulnerability, tracked as CVE-2026-65400, is under active exploitation. The agency said it received a notification that abuse of the flaw has been observed on multiple systems where port 5900 was reachable from the Internet. In every case it reviewed, the attacker had obtained root access on the affected Mac and planted a Monero crypto miner. The bug sits in macOS's screen-sharing feature, the built-in capability that lets a remote party view the screen and control the keyboard and mouse while the machine is on. Apple traced the root cause to a flaw in "state management," the mechanism that tracks preceding events, user interactions, variables and other system states. The vulnerability carries a severity rating of 7.1 out of 10. Apple patched it last week for macOS Tahoe, Sequoia and Sonoma. Details of CVE-2026-65400 became public at last week's Black Hat security conference. Apple's own advisory describes the flaw only in hedged terms, saying it "may" allow an attacker without credentials to gain access to a Mac; the article notes it is unclear why Apple chose that softer wording, though hedging language of this kind is common across the industry when vendors disclose vulnerabilities. A video demonstrating the exploit in action has also been published.
Key facts
- CVE-2026-65400 is a macOS screen-sharing vulnerability rated 7.1 out of 10 in severity.
- The Netherlands National Cyber Security Centrum says the flaw is under active exploitation on systems with port 5900 exposed to the Internet.
- Attackers gained root access and installed Monero crypto miners on every affected system the NCSC reviewed.
- Apple patched the bug last week for macOS Tahoe, Sequoia and Sonoma, tracing the cause to a state-management flaw.
- Details of the vulnerability went public at last week's Black Hat conference, and a video of the exploit has circulated.
Why it matters
This is not a theoretical flaw sitting in a disclosure report. A national cybersecurity agency is confirming live exploitation, with attackers reaching root and dropping cryptominers on real machines before most owners had a chance to patch. A screen-sharing bug that hands over keyboard and mouse control is about as close to full remote takeover as a single CVE gets.
Who it affects
Mac users running macOS Tahoe, Sequoia or Sonoma with screen sharing enabled and port 5900, the standard port for remote screen-sharing and VNC-style access, reachable from the open Internet. Machines behind a firewall or without screen sharing turned on are outside the specific exposure the NCSC described.
How to use it
Install Apple's patch for CVE-2026-65400 immediately if it has not already been applied. Beyond patching, check whether screen sharing is enabled at all, and if it is, confirm port 5900 is not exposed directly to the Internet; put it behind a firewall or VPN instead. The article opens by asking readers directly whether they know if their screen sharing is on, worth treating as a literal checklist item.
How solid is it
The warning comes from a national government cybersecurity agency (the NCSC), which is a credible, non-vendor source, and it is corroborated by Apple's own patch release and advisory. The underlying technical cause, a state-management flaw, is described consistently by both the patch notes and the reporting. The one gap is scale: neither the NCSC nor Apple has given a count of how many systems were compromised or how many Macs remain vulnerable worldwide, so the warning establishes that exploitation is real without establishing how widespread it is.
Risks and caveats
Apple's advisory hedges, saying the flaw "may" allow an attacker without credentials to gain access, and the article itself notes it is unclear why Apple chose that softer language rather than a firmer statement, though it points out such hedging is common industry practice. The NCSC's confirmed cases all involve Monero mining, but a state-management bug that grants root access could in principle be used for more than cryptomining; no broader payloads have been reported so far. No information is available on who is behind the attacks.
“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet. In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”
— Netherlands National Cyber Security Centrum (NCSC)