DUTCH officials have reported that CVE-2026-65400, a severe macOS vulnerability, is being actively exploited, allowing attackers to gain full control of Macs by executing malicious code. This vulnerability is linked to the macOS screen sharing feature and can be triggered when port 5900 is exposed to the internet. It received a patch from Apple for various macOS versions and has a severity rating of 7.1 out of 10. The exploit has resulted in the installation of Monero crypto miners on affected systems.
Users are advised to disable screen sharing unless needed, keep port 5900 closed, and install the latest security updates to mitigate risks of further exploitation.