macOS Screen Sharing Flaw Actively Exploited to Deploy Monero Miners
A critical authentication bypass vulnerability in **macOS Screen Sharing**, identified as **CVE-2026-65400**, is being actively exploited in the wild. Attackers are leveraging this flaw to gain root access on vulnerable systems, particularly those with port 5900 exposed, and subsequently deploying **Monero** cryptocurrency miners.
The **Netherlandsβ National Cyber Security Centre (NCSC)** has issued an urgent warning regarding active exploitation of a **macOS** authentication bypass vulnerability. The flaw affects the built-in **Screen Sharing** feature, which utilizes the **VNC** protocol over **TCP port 5900** for remote desktop control.
**Apple** addressed **CVE-2026-65400** on August 6 in **macOS Tahoe 26.6.1** and earlier versions. This vulnerability allowed network-based attackers to bypass authentication and gain unauthorized access to systems.

Upon successful exploitation, an attacker could remotely open applications, access files, modify security settings, and execute various other malicious actions.
In an update to its initial advisory, the **NCSC** confirmed receiving reports of active exploitation where **port 5900** was exposed to the internet. The agency noted that in observed attacks, the perpetrators achieved root access and installed **Monero** cryptocurrency mining software.
βThe NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,β states the Dutch agency's update. βIn all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed.β
To mitigate the risk, **macOS** users are strongly advised to update their systems to one of the following patched releases:
* **macOS Tahoe 26.6.1**
* **macOS Sequoia 15.7.9**
* **macOS Sonoma 14.8.9**
These updates enhance state management mechanisms to ensure proper credential validation and prevent unauthorized authentication attempts.
For users unable to update immediately, disabling **Screen Sharing** through System Settings (General β Sharing β Screen Sharing) is a recommended interim solution if the feature is not essential.
The **NCSC** has not yet disclosed further specifics regarding the scale of these attacks, their commencement, or whether they extend beyond cryptocurrency mining operations.