Apple Fixes macOS Flaw Exploited for Mass Monero Mining
Apple has patched a critical macOS vulnerability after attackers exploited internet-facing Macs to gain root access and install Monero mining software, according to an updated warning from the Netherlands' National Cyber Security Centre.
The vulnerability, identified as CVE-2026-65400, was caused by an improper state management flaw that allowed an attacker on the network to access Screen Sharing without valid credentials. This meant that changing a Screen Sharing password or disabling legacy VNC authentication would not fix the issue.
Huntress researcher Ryan Dowd said a Censys search identified 'tens of thousands of potentially vulnerable hosts', which covers Macs that appeared exposed to the internet and should not be interpreted as tens of thousands of confirmed compromises. The risk is particularly relevant to hosted bare-metal Macs, including Mac minis rented for remote workloads.
The National Vulnerability Database shows that CISA upgraded the scoring on August 14 after initially assigning a lower severity assessment. The Dutch NCSC has not disclosed how many Macs were compromised or identified the attackers, but they confirmed active exploitation of CVE-2026-65400 on multiple systems with port 5900 exposed to the internet.