Vulnerability giving attackers full control of Macs is under active exploitation

A high-severity vulnerability in macOS screen-sharing, tracked as CVE-2026-65400, is being actively exploited by attackers to gain root access. The flaw allows remote code execution when port 5900 is exposed to the internet.
Why it matters
This represents a significant security risk for Mac users, as it allows unauthorized remote control of systems and the installation of malicious software like crypto miners.
GETTING ROOT IS EASY Vulnerability giving attackers full control of Macs is under active exploitation Screen-sharing bug lets remote hackers log in without a password.
81 Isolated photo a 13 inch MacBook Pro Retina. Credit: Getty Images Isolated photo a 13 inch MacBook Pro Retina. Credit: Getty Images Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation.
“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in