arstechnica.com 8/14/2026, 6:45:52 PM · external

Apple patches CVE-2026-65400 macOS flaw after crypto miner attacks

Apple patches CVE-2026-65400 macOS flaw after crypto miner attacks
Developing story vulnerability 2 articles tracked
Apple patches actively exploited macOS vulnerability CVE-2026-65400
CyberSIXT Evidence Panel
Primary Source advisories.ncsc.nl
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

DUTCH officials have reported that CVE-2026-65400, a severe macOS vulnerability, is being actively exploited, allowing attackers to gain full control of Macs by executing malicious code. This vulnerability is linked to the macOS screen sharing feature and can be triggered when port 5900 is exposed to the internet. It received a patch from Apple for various macOS versions and has a severity rating of 7.1 out of 10. The exploit has resulted in the installation of Monero crypto miners on affected systems.

Users are advised to disable screen sharing unless needed, keep port 5900 closed, and install the latest security updates to mitigate risks of further exploitation.

View Primary Source Via arstechnica.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline