HACKERS are exploiting a critical macOS Screen Sharing vulnerability (CVE-2026-65400) that allows unauthorized access to systems where port 5900 is exposed online. The flaw, confirmed by the Dutch National Cyber Security Centre, enables attackers to gain root access and deploy Monero cryptocurrency miners. Apple released patches in macOS updates, but reports of active exploitation surfaced shortly after. The vulnerability is associated with authentication issues in macOS’s Screen Sharing feature.
Security experts emphasize that the time between vulnerability discovery and exploit availability is shrinking, posing increased risks to users.