CYBERSECURITYTRACKER
TRACKING4,111 stories770 vuln stories
Permanent story citation

Vulnerability giving attackers full control of Macs is under active exploitation

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4474

As cited

Citation snapshot as of .

vulnerabilities

Vulnerability giving attackers full control of Macs is under active exploitation

A high-severity macOS vulnerability (CVE-2026-65400) in the screen sharing feature allows remote code execution with root privileges and is currently being exploited in the wild. The Netherlands National Cyber Security Centrum reported active abuse on systems with port 5900 exposed to the internet, where attackers installed Monero crypto miners after gaining access. Apple released patches for macOS Tahoe, Sequoia, and Sonoma last week.

Why it matters: Mac users with screen sharing enabled and port 5900 exposed need to patch immediately; attackers are actively deploying crypto miners and establishing root access on vulnerable systems.

Source published
First seen by Cybersecurity Tracker

Source attribution