A critical macOS Screen Sharing vulnerability, CVE-2026-65400, is under active exploitation, with attackers gaining root access and installing Monero cryptocurrency miners on unpatched Macs. The Dutch National Cyber Security Centre (NCSC-NL) reported on August 12 that in all confirmed cases, affected systems had port 5900 exposed to the internet, and attackers placed a Monero miner after gaining root access . Apple patched the flaw on August 6 in an out-of-band update for macOS Tahoe, Sequoia, and Sonoma . The vulnerability allows an attacker on the network to authenticate to Screen Sharing without valid credentials, effectively giving them full control of the machine .
Sources disagree on the severity rating. NCSC-NL initially scored it 7.1 (high) under CVSS v3, while CISA later raised it to 9.8 (critical) on August 14, assessing the attack as automatable . Ars Technica also cites the 7.1 figure . NIST has not yet assessed the vulnerability .
Security firm Calif used an AI agent to produce working exploits for two pre-authentication root bugs in macOS within four hours, highlighting the speed at which patches can be reverse-engineered into exploits .
Users are urged to update macOS immediately. If updating is not possible, disabling Screen Sharing in System Settings and keeping port 5900 closed are recommended . The vulnerability is also similar to a recent Zoom screen-sharing bug .
