A critical macOS authentication flaw, identified as CVE-2026-65400, is being actively exploited by hackers to gain root access and deploy Monero miners on vulnerable Macs. The bug, which has a CVSS score of 9.8, resides in the built-in Screen Sharing feature and allows attackers to authenticate without proper credentials. Hackers are targeting Macs with port 5900 exposed online, taking advantage of the flaw to install cryptocurrency mining software. The Dutch National Cyber Security Centre has confirmed the active exploitation of this vulnerability, which was recently patched by Apple1. The fact that hackers are already exploiting this flaw less than two weeks after the fix was released underscores the importance of prompt patching. This vulnerability matters to practitioners because it highlights the need for swift action in applying security updates to prevent unauthorized access and malicious activity on their systems.