A remote desktop feature built into every modern Mac has become an open door for hackers, and Dutch cybersecurity officials say the break-in is already happening. Security researchers and government agencies are now warning users about an actively exploited macOS screen sharing vulnerability that lets attackers take control of a computer without ever needing a password, then quietly install cryptocurrency mining software on the machine.
Key takeaways
- The flaw, tracked as CVE-2026-65400, carries a severity rating of 7.1 out of 10 and lets attackers execute code remotely without valid credentials.
- The Netherlands’ National Cyber Security Centrum (NCSC) confirmed active exploitation on systems where port 5900 was reachable from the internet.
- Attackers who exploited the bug gained root access and installed Monero crypto miners on affected Macs.
- Apple patched the issue last week in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
- Users can reduce risk by disabling Screen Sharing when it’s not in use and installing the latest security update.
High-Severity macOS Vulnerability Allows Remote Code Execution
CVE-2026-65400 is a bug that lets a remote attacker run malicious code on a Mac without needing a username or password. Apple’s built-in Screen Sharing feature, which uses the VNC protocol to let one computer view and control another over a network, is at the center of the problem.
Nature and Source of the Vulnerability
The root cause traces back to how macOS handles “state management” inside the screen sharing system — the internal bookkeeping that tracks prior events, user interactions, and system variables. A flaw in that logic allows an intruder to sidestep proper credential checks entirely. In practical terms, someone connecting to a vulnerable Mac’s screen sharing port doesn’t need to prove who they are before gaining access.
Severity Rating and Technical Details
Apple and security researchers rate the flaw at 7.1 out of 10, a score that lands it in high-severity territory without reaching the maximum critical tier. Details of the bug first became public at last week’s Black Hat security conference, and Apple’s own advisory described the issue cautiously, saying the vulnerability “may” allow an attacker without credentials to access a Mac. That kind of hedged language is fairly typical across the tech industry when companies disclose security flaws, even when exploitation is already confirmed in the wild.
Active Exploitation Confirmed by Dutch National Cyber Security Centrum
The NCSC says it has already received reports of real-world attacks exploiting this macOS screen sharing vulnerability, not just theoretical risk. In an advisory update, the agency stated it had received a notification indicating active abuse of the flaw on multiple systems where port 5900 was accessible from the internet.





