Dutch NCSC confirms live attacks on macOS Screen Sharing bug

Attackers are exploiting CVE-2026-65400 to drop Monero miners on exposed Macs.

CSBadmin
2 Min Read

Mac owners running Screen Sharing with port 5900 exposed to the internet should patch immediately. The Dutch NCSC-NL has confirmed attackers are actively exploiting the macOS authentication flaw CVE-2026-65400, rated CVSS 9.8, to take root on unpatched machines and plant Monero miners.

The bug sits in the remote desktop service built into every Mac. Apple’s fix reworked how the service manages authentication state. Before the patch, a network attacker could pass themselves off as an approved Screen Sharing user with no real credentials. Fixes landed in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

NCSC-NL said reports of live abuse arrived from multiple systems where port 5900 was reachable straight from the internet. Every case documented so far ended the same way: root access obtained, then a Monero cryptocurrency miner dropped on the machine. The payload reads as opportunistic scanning rather than a targeted operation, though the root foothold itself enables far worse outcomes.

Two related Screen Sharing bugs, patched a month earlier in macOS 26.6, trace back to the same source file. One was a pre-authentication hole that researcher @osxreverser said needed nothing but a target’s IP address to trigger. His scan turned up roughly 40,000 exposed hosts, close to half in the US.

Security firm Calif dissected both flaws and found no memory corruption and no race conditions, only logic errors. A few correctly sequenced packets were enough to walk past authentication. Calif also built working exploits for both in about four hours with an AI coding agent, a reminder that the window between patch publication and weaponized exploit keeps shrinking.

If patching is not possible right away, disable Screen Sharing under System Settings until the update applies. Leaving port 5900 open to the internet at this point is effectively an invitation.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.