Actively exploited macOS vulnerability gives attackers full control of Macs
Dutch cybersecurity authorities have warned about an actively exploited high-severity macOS vulnerability that allows remote code execution. Apple has issued patches, but attacks have already resulted in root access and Monero miner installations.

Dutch cybersecurity authorities have issued an urgent warning about a high-severity macOS vulnerability that is currently being exploited in active attacks. The flaw, known as CVE-2026-65400, allows remote code execution and could give attackers full control over affected Macs. Apple released patches last week for macOS Tahoe, Sequoia, and Sonoma to remediate the issue.
The Netherlands National Cyber Security Centrum (NCSC) reported that it had observed active abuse on multiple systems where port 5900 was exposed to the internet. In all recorded incidents, the attackers gained root access and deployed a Monero cryptocurrency miner. Port 5900 is typically associated with the macOS screen sharing feature, which lets remote users view the display and control the mouse and keyboard.
The vulnerability carries a severity score of 7.1 out of 10. The root cause lies in a state management flaw within the screen sharing component. State management is the mechanism responsible for tracking ongoing events, user interactions, variables, and other system states. This defect can be exploited remotely without valid credentials, according to Apple's advisory.
Technical details of CVE-2026-65400 went public at last week's Black Hat security conference. Apple's security note uses the word "may" when describing the possibility of an attacker gaining access without credentials. While the company did not elaborate, such hedging language is common in vulnerability disclosures from major software vendors.
The NCSC's findings indicate that the main risk is for users who have enabled screen sharing and exposed port 5900 to the internet. Applying the latest Apple updates is critical to mitigating the threat.


