NewsNovo

macOS screen sharing flaw is actively exploited, Dutch security officials warn

8/15/2026

A macOS vulnerability tracked as CVE-2026-65400 is under confirmed active attack: the Netherlands National Cyber Security Centrum reported that attackers have reached root on multiple systems and installed a Monero cryptocurrency miner on each.

Apple last week released a patch covering macOS Tahoe, Sequoia, and Sonoma. The fix exists; the question is how many machines have applied it. The NCSC was specific about what it observed.

On affected systems, port 5900, the default port for macOS screen sharing, was internet-accessible.

Screen sharing is the built-in feature that lets a remote party view a machine's display and control its keyboard and mouse while the machine is on.

Keep reading

Read the full story

Open on NewsNovo