Overview
- The Netherlands’ National Cyber Security Centre reported that it observed active exploitation on multiple Macs where Screen Sharing’s VNC port (TCP 5900) was reachable from the internet.
- The flaw, tracked as CVE-2026-65400, is a state‑management authentication bug in built‑in macOS Screen Sharing that can let attackers establish sessions without valid credentials.
- In reported incidents attackers obtained root on affected machines and deployed a Monero cryptocurrency miner, and agencies warn the full scope of compromises is still unknown.
- Apple issued fixes (for Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9) and authorities advise immediate updates or, if updates cannot be applied, disabling Screen Sharing and blocking TCP 5900 from the internet.
- Admins should inventory Macs exposed to the internet, look for unexpected Screen Sharing sessions, root processes or sustained high CPU and egress to miner pools, and assume full compromise if root access is confirmed.