Hackers exploited macOS Screen Sharing flaw to install Monero miners, Dutch cyber agency says
U.S. officials rated the severity of the vulnerability a critical 9.8/10 on the CVSS scale, and experts are warning users to update their devices.
The Dutch National Cyber Security Centre (NCSC-NL) reported that attackers are exploiting a vulnerability in macOS Screen Sharing, tracked as CVE-2026-65400, to compromise Macs with port 5900 exposed to the Internet. According to Tom's Hardware, in every case reported to the agency, attackers obtained root access and installed a Monero cryptocurrency miner.
The vulnerability, an authentication bypass, was patched by Apple on August 6 in an out-of-band update covering macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The US Cybersecurity and Infrastructure Security Agency (CISA) rated the severity of the vulnerability a critical 9.8/10 on the CVSS scale, as reported by The Block.
NCSC-NL first flagged the vulnerability in an advisory on August 7, urging organizations to update immediately, and revised it on August 12, noting that public proof-of-concept code is now available and that active abuse had been observed on multiple internet-exposed systems.
Brief written by urgent.news from The Block, Tom's Hardware, Dev.to — 3 reports on this story. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.