Dutch cyber officials warn that CVE-2026-65400, a critical macOS vulnerability rated 7.1/10, is under active exploitation by attackers exposing port 5900 to the internet. The flaw in macOS screen sharing state management allows unauthenticated attackers to gain full root control and deploy Monero crypto miners on affected systems.
Background
Apple released a patch for CVE-2026-65400 last week covering macOS Tahoe, Sequoia, and Sonoma. The vulnerability was disclosed at the Black Hat security conference and affects the VNC-based screen sharing feature when port 5900 is exposed to the internet.
- Source
- Ars Technica
- Published
- Aug 15, 2026 at 02:32 AM
- Score
- 8.0 / 10