
The Netherlands’ National Cyber Security Center (NCSC) is warning that hackers are actively using a vulnerability to bypass macOS authentication after exploit code became public.
The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop management over a network using the VNC protocol over TCP port 5900.
An apple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier. The vulnerability allows network attackers to gain access without valid credentials.
An attacker can use this access to remotely open applications, access files, change security settings, and perform various other actions.
In an update to the original advisory, the Dutch agency said it had received a report indicating that the vulnerability was being exploited in the wild in attacks where port 5900 was exposed to the Internet.
According to the NCSC, the attacker gained root access to the system and deployed a Monero cryptocurrency miner.
“NCSC has received notification indicating that active abuse of this vulnerability has been observed on multiple systems where port 5900 was accessible from the Internet,” it reads Dutch agency update.
“In all of these cases, the root of the affected system was accessed and a Monero crypto miner was planted.”
macOS users are advised to upgrade their system to one of the following versions that address CVE-2026-65400:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
These releases improve state management mechanisms to enforce proper credential validation and prevent fraudulent authentication attempts.
When system updates are not immediately possible, users can use system settings to disable screen sharing (General → Sharing → Screen Sharing) if not needed.
NSCS has not shared any details about the reported attacks, when they started, whether they extend beyond cryptocurrency mining, or how many systems were affected.
Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.
The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

