
The Netherlands National Cyber Security Centrum has reported active exploitation of a high-severity macOS vulnerability that permits remote attackers to execute malicious code without authentication. The agency indicated that the vulnerability, identified as CVE-2026-65400, has been observed being abused on multiple systems where port 5900 was exposed to internet access. In all documented cases, attackers achieved root-level access and subsequently installed Monero cryptocurrency mining software.
The vulnerability originates from a flaw in macOS screen-sharing functionality, which enables remote parties to view and control a computer’s display, keyboard, and mouse when the system is powered on. A defect in state management—the mechanism tracking preceding events, user interactions, variables, and system conditions—forms the basis of the security issue. The vulnerability affects macOS Tahoe, Sequoia, and Sonoma, with Apple releasing patches last week. The issue carries a severity rating of 7.1 out of 10.
Public disclosure of the vulnerability’s details occurred at last week’s Black Hat security conference. Apple acknowledged that CVE-2026-65400 may allow unauthenticated attackers to access a Mac, with security firm Bynario credited for discovering and reporting the flaw. The vulnerability becomes accessible when port 5900, which the macOS firewall opens during screen-sharing activation, is left open to internet connections. Most routers and firewalls block this port by default unless specifically configured otherwise.
Security experts recommend that Mac users keep port 5900 closed and utilize alternative connection methods such as virtual private networks or SSH tunneling when requiring remote access. The most effective mitigation strategy involves disabling screen sharing when not in active use, enabling the feature only when necessary, and promptly disabling it afterward. Users can manage screen sharing through System Settings under General and Sharing options. Installation of the recently released security update is also essential.
Current evidence indicates that exploitation has been limited to cryptocurrency mining installations, which consume system resources to perform computational operations generating cryptocurrency for attackers. However, security analysts warn of broader potential risks, including the possibility that attackers could utilize the vulnerability to deploy malware designed to harvest credentials or execute other damaging activities.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI