securityaffairs.com 8/15/2026, 9:46:25 AM · external

Hackers exploit CVE-2026-65400 to mine Monero on macOS

Hackers exploit CVE-2026-65400 to mine Monero on macOS
Developing story vulnerability 3 articles tracked
Apple patches actively exploited macOS vulnerability CVE-2026-65400
CyberSIXT Evidence Panel
Primary Source support.apple.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

HACKERS are exploiting a critical macOS Screen Sharing vulnerability (CVE-2026-65400) that allows unauthorized access to systems where port 5900 is exposed online. The flaw, confirmed by the Dutch National Cyber Security Centre, enables attackers to gain root access and deploy Monero cryptocurrency miners. Apple released patches in macOS updates, but reports of active exploitation surfaced shortly after. The vulnerability is associated with authentication issues in macOS’s Screen Sharing feature.

Security experts emphasize that the time between vulnerability discovery and exploit availability is shrinking, posing increased risks to users.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline