
Attackers are actively exploiting a critical authentication bypass in macOS Screen Sharing — the built-in remote desktop feature that runs on TCP port 5900 — less than two weeks after Apple released a patch. The Netherlands’ National Cyber Security Centre (NCSC) issued a warning after confirming the vulnerability, tracked as CVE-2026-65400, is being abused in the wild.
In observed attacks, hackers gained root access to internet-exposed Macs and installed a Monero cryptocurrency miner. The Dutch agency says the pattern repeats across multiple affected systems, all of which had port 5900 reachable from the public internet. Apple fixed the flaw on August 6, 2026 as part of macOS Tahoe 26.6.1 and earlier supported releases. An attacker who exploits the flaw can open applications remotely, access files, change security settings, and run arbitrary commands — in these cases they chose to silently drain the machine’s resources for cryptomining.
How to check if you’re affected
Affected versions are any macOS release older than Tahoe 26.6.1 with Screen Sharing enabled. To check: open System Settings → General → Sharing and look for “Screen Sharing.” If it is turned on and your Mac is reachable from the internet — for example in a server room, on a business network with port forwarding, or exposed via a public IP — update immediately. Run System Settings → General → Software Update and install any pending macOS updates. If you cannot update right away, disable Screen Sharing until you can.
