The Netherlands’ National Cyber Security Centre says CVE-2026-65400 in macOS Screen Sharing is being actively exploited after public exploit code appeared. Attackers are using exposed port 5900 to gain root access and install a Monero miner on affected systems. #CVE-2026-65400 #macOS #NCSC #Monero
Keypoints
- Hackers are exploiting a macOS authentication bypass vulnerability in the wild.
- The flaw affects macOS Screen Sharing over VNC on TCP port 5900.
- Apple fixed CVE-2026-65400 in macOS Tahoe 26.6.1 and related releases.
- Attackers can gain access without valid credentials and obtain root privileges.
- The NCSC observed compromised systems being used to deploy a Monero miner.