All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Mac Screen Sharing Vulnerability Actively Exploited, Dutch Officials Warn

Created at 14 Aug · 6:36 PM1 source↑ Market-relevant
IN SHORT

A critical macOS vulnerability allowing remote attackers to gain full control of Macs without a password is under active exploitation, Dutch cybersecurity officials warned. The flaw, tracked as CVE-2026-65400, has been patched by Apple, but attackers are exploiting it when port 5900 is accessible.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

7.1/10vulnerability severity rating
5900port accessible for exploitation

Who's Involved

Netherlands National Cyber Security Centrum
warned of active exploitation of macOS vulnerability
Apple
released a patch for the vulnerability
Mac Screen Sharing Vulnerability Actively Exploited, Dutch Officials Warn

↳ Why This Matters

This vulnerability poses a significant risk to Mac users, as it allows remote attackers to gain full control of their devices without needing any credentials, potentially leading to data theft or the installation of further malicious software beyond cryptocurrency miners.

Key facts

  • A critical macOS vulnerability, CVE-2026-65400, allows remote attackers to gain full control of Macs.
  • The vulnerability is being actively exploited, with attackers accessing root privileges and installing Monero miners.
  • The flaw is in the macOS screen sharing feature, which opens port 5900 when enabled.
  • Apple released a patch for the vulnerability last week for macOS Tahoe, Sequoia, and Sonoma.
  • Security officials advise users to keep port 5900 closed, enable screen sharing only when needed, and turn it off afterward.

Dutch officials have issued a warning regarding a critical vulnerability in macOS that allows attackers to gain complete control over affected Macs. The flaw, tracked as CVE-2026-65400, is reportedly under active exploitation, with attackers observed gaining root access and installing Monero cryptocurrency miners on compromised systems, particularly when port 5900 is accessible from the internet.

The vulnerability stems from a bug in the macOS screen sharing capability, which, when enabled, opens port 5900. This feature allows a remote party to view the screen and control the keyboard and mouse. The underlying cause is a flaw in the system's "state management." Apple released a patch for this vulnerability last week, addressing macOS Tahoe, Sequoia, and Sonoma. The severity rating for CVE-2026-65400 is 7.1 out of 10.

Details of the exploit became public at the Black Hat security conference. While Apple stated the vulnerability "may" allow an attacker without credentials to gain access, security practitioners generally recommend keeping port 5900 closed even when screen sharing is in use, suggesting alternatives like VPNs or SSH tunneling. The safest practice involves blocking screen sharing by default, enabling it only when necessary, and disabling it after use. Installing the latest security updates is also crucial.

Frequently asked questions

CVE-2026-65400 is a high-severity vulnerability in macOS that allows remote attackers to gain full control of a Mac without a password, typically by exploiting the screen sharing feature.

Your Mac is vulnerable if it is running an unpatched version of macOS Tahoe, Sequoia, or Sonoma and has port 5900 accessible from the internet, which can occur when screen sharing is enabled.

Currently, exploited instances have involved attackers gaining root access and installing Monero cryptocurrency miners. However, there is a risk they could install more nefarious malware.

Install the latest security updates from Apple, keep port 5900 closed, enable screen sharing only when needed, and disable it after use.

What Happens Next

01Users should install the latest security updates from Apple.
02Users should review and secure their screen sharing settings, closing port 5900 when not in use.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

A high-severity macOS vulnerability allowing remote code execution was identified.
Dutch officials warned of active exploitation of the vulnerability, with attackers accessing root and installing Monero miners.
The vulnerability, CVE-2026-65400, stems from a bug in the macOS screen sharing capability.
Apple released a patch for macOS Tahoe, Sequoia, and Sonoma last week.
Details of the vulnerability were made public at the Black Hat security conference.
Exploitation occurs when port 5900, used by screen sharing, is exposed to the internet.

Sources

T1
Vulnerability giving attackers full control of Macs is under active exploitationvar abtest_2167685 = new ABTest(2167685, 'impression');Ars Technica

Related Stories

Apple warns users of mercenary spyware attacks
13 Aug · 10:11 PM
OpenAI Staff Cite Safety Lapses Amid AI Agent Breach
14 Aug · 6:36 PM
Man attempts to manipulate court with hidden AI prompts in filings
14 Aug · 5:31 PM
Rocket Lab unveils portable spaceport; Blue Origin plans dual launch pads
14 Aug · 11:06 AM
Czinger debuts topology-optimized brakes with 21C Spyder
14 Aug · 7:06 AM