Apple Patches Critical macOS Vulnerability Exploited for Monero Mining
Apple has patched a critical macOS vulnerability that allowed attackers to gain root access and install Monero mining software on internet-facing Macs. The Netherlands' National Cyber Security Centre (NCSC) confirmed active exploitation of CVE-2026-65400, which affects macOS Screen Sharing services.
The flaw was discovered by security firm Huntress, who found that tens of thousands of potentially vulnerable hosts were exposed to the internet. Huntress researcher Ryan Dowd noted that changing a Screen Sharing password or disabling legacy VNC authentication does not address the vulnerability.
Apple patched CVE-2026-65400 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 on August 6. The company described it as an authentication flaw caused by improper state management that could allow an attacker on the network to access Screen Sharing without valid credentials.
The Dutch NCSC updated its advisory on August 12 to confirm active exploitation of CVE-2026-65400 on multiple systems with port 5900 exposed to the internet. In every reported case, attackers obtained root access and installed a Monero miner.