Dutch NCSC Warns of Active Exploitation of macOS Screen Sharing Flaw to Deploy Monero Miners
The Netherlands' NCSC reports active attacks exploiting a macOS Screen Sharing authentication bypass (CVE-2026-65400) to install Monero miners on systems with port 5900 exposed.
This article was drafted with AI assistance from multiple sources and was reviewed and approved by a human editor before publication.
The Dutch National Cyber Security Centre (NCSC) has issued a warning about active exploitation of a macOS vulnerability that allows attackers to bypass authentication in the built-in Screen Sharing feature. Tracked as CVE-2026-65400, the flaw has been used in the wild to deploy cryptocurrency miners on affected systems.
Screen Sharing is a remote desktop tool that relies on the Virtual Network Computing (VNC) protocol and listens on TCP port 5900. The vulnerability stems from a flaw in the feature's state management, a mechanism that tracks user interactions, variables, and other system states. Because of this flaw, network-based attackers can gain access without valid credentials, potentially opening applications, accessing files, changing security settings, and performing other actions.
Apple addressed the issue on August 6 with updates to macOS Tahoe 26.6.1, as well as Sequoia and Sonoma. The company says the patches improve state management mechanisms to ensure correct credential validation and block rogue authentication attempts. The severity of CVE-2026-65400 has been rated 7.1 out of 10.
The NCSC's advisory notes that the vulnerability is being actively abused on systems where port 5900 is exposed to the internet. "The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet," the agency stated. In these incidents, attackers obtained root access and installed a Monero miner. "In all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed," the NCSC added.
The agency has not disclosed further details about the attacks, such as when they began, whether they extend beyond cryptocurrency mining, or the number of systems affected.
For users who cannot apply the updates immediately, the NCSC recommends disabling Screen Sharing through System Settings under General, then Sharing, and toggling off Screen Sharing. This mitigates the risk of remote exploitation until patches can be installed.