A critical macOS authentication flaw, identified as CVE-2026-65400, is being actively exploited by hackers to gain root access and deploy Monero miners on vulnerable Macs. The bug, which has a CVSS score of 9.8, resides in the built-in Screen Sharing feature and allows attackers to authenticate without proper credentials. Hackers are targeting Macs with port 5900 exposed online, taking advantage of the flaw to install cryptocurrency mining software. The Dutch National Cyber Security Centre has confirmed the active exploitation of this vulnerability, which was recently patched by Apple1. The fact that hackers are already exploiting this flaw less than two weeks after the fix was released underscores the importance of prompt patching. This vulnerability matters to practitioners because it highlights the need for swift action in applying security updates to prevent unauthorized access and malicious activity on their systems.
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
⚠️ Critical Alert
Why This Matters
CVE-2026-65400 is in active discussion involving Apple — exploitation status determines whether this is patch-now or monitor.
References
- SecurityAffairs. (2026, August 15). macOS Screen Sharing Flaw Exploited to Deploy Monero Miners. *SecurityAffairs*. https://securityaffairs.com/197234/uncategorized/macos-screen-sharing-flaw-exploited-to-deploy-monero-miners.html
Original Source
SecurityAffairs
Read original →