(Vulnerability giving attackers full control of Macs is under active exploitation)

The Netherlands National Cyber Security Center (NCSC) said this week that a “highly dangerous” bug in macOS is already being exploited. This warning applies to computers where Screen Sharing is enabled and TCP port 5900 is open to the Internet. In the cases NCSC analyzed, attackers gained root access to the compromised Macs and installed a Monero crypto miner on them.
That pair will be obvious to people who keep Screen Sharing turned on for “just in case” or to get help from afar. This is a very useful feature. It’s also the surface this CVE is sitting on. Last week, Apple issued a fix. If you haven't already, this is the first thing you should do.


What the NCSC has revealed
They told the NCSC they were aware the weakness was being used against a large number of different systems. The problem was not a particular set of apps, or a particular model of Mac. It was the openness. Port 5900 was open to everybody.
In all the cases that were observed, two things occurred. Root was privy to the system in question. We put an AMONero miner in the machine. Monero miners use their CPUs (or sometimes GPUs) to mine cryptocurrency for other people in the background. Fans, load or battery when you watch them, they make a lot of noise. When you're gone, they don't talk.
The NCSC did not provide a number of victims, a name for the campaign or a list of affected industries. People know there are more than two systems. Port 5900, root and miner. That’s enough to turn this from a suggestion into an actual problem.


The CVE, in a very short
The bug is identified as CVE-2026-65400. Severity 7.1/10. macOS has a feature named Screen Sharing. It allows someone else to view the screen and control the keyboard and mouse while the machine is running.
The problem was due to what is being called a “state management” bug. Screen Sharing basically keeps track of the system’s history, who has used the system, variables and other states. The way those books are kept is wrong. This is what the people should be told. It's not a recipe and you don't need a recipe to know what to do.


Details on CVE-2026-65400 were publicly disclosed at last week’s Black Hat security conference. Apple said a CVE could be used by an attacker without credentials to get onto a Mac. Often these disclosures are in weak vendor language. Don't use the hedge as an excuse for procrastination.
There is a video of a hack . You don't have to see it, describe it or put it together again. The facts of the operation are already out there. Screen Sharing, port 5900, no credentials required in Apple's own words, active abuse, patch available.
But who is at risk?
Most Macs have Screen Sharing turned off by default. And it begins when someone turns it on. If you turn on Screen Sharing, the macOS firewall will open port 5900 . But that is the firewall on the local machine, not the one at your office.
Many routers and firewalls will block 5900 unless you open a forward or similar hole. To connect to a Mac from the internet on port 5900 you need to be behind a normal home or office NAT and not have a port-forward rule setup. But the story is different for a Mac with a public address, a lab network that isn't well-split, a VPS style colocation, a "DMZ host" setting or a router forwarding 5900.
The second was taken advantage of by the NCSC. The problem is the filter is looking at the internet. 5900 is not reachable from outside if it is not possible in this case of abuse. If you can dial 5900, you're in the group the NCSC warned about.


This is a typical group of people that frontend engineers work with. Support sessions and “can you look at my machine?” habits often cause people to turn off Screen Sharing. The set could be a Mac Mini used as a build box, a computer a designer uses to give a contractor remote access, or a personal laptop that's sometimes connected to a network and has a port forwarded. The risk is not "You write React". http://5900 on the internet risk.
What they are, and what Apple has patched
Apple just patched CVE-2026-65400 for the current supported lines of macOS Tahoe, Sequoia and Sonoma last week. Sonoma 14.8.9 Tahoe 26.6.1 Sequoia 15.7.9 macOS Tahoe 26.6.1


These strings are so important. "Just updated" is NOT the same as "I am on 26.6.1, 15.7.9 or 14.8.9." Check About This Mac or Software Update to ensure you're on the right build. If you have more than one Mac, check them all. A patched laptop next to a Mini that is unpatched and still has Screen Sharing enabled is not a pass.
Apple did not include older unsupported releases of macOS on these versions. This is why they are not a backport story. If you’re still on an older line, you don’t have those three patch versions to stand on.


What do I do today?
Patch first. Download last week’s security update for macOS Tahoe 26.6.1, Sequoia 15.7.9 or Sonoma 14.8.9. If the updater tells you to reboot, do so. Version: 1.0.1 Check version when done.
Next, switch Screen Sharing On or Off as desired. Keep it off unless you need to use it for a session, turn it off when the session is over. To share your screen, go to System Settings > General > Sharing and tick the box next to it. Again, head to System Preferences > General > Sharing and now you’re in control.
If you want to see and control things from far away, don't open port 5900 to the Internet while Screen Sharing is running. If you connect through a VPN or SSH tunnel the Mac does not advertize 5900 as a public service. Most routers block 5900 and you need to forward it. Most important thing, it's a good place for a family. If there's one just delete the forwarding.
As explained, there are only two ways to protect against this CVE: patch and don’t put 5900 on the public Internet. Another lock is ensuring that machines that do not need the feature are not left to their own devices. It turns off Screen Sharing when you are not in a session.
Send the same list to anyone you help with their Mac to ensure they’re on Tahoe 26.6.1, Sequoia 15.7.9 or Sonoma 14.8.9. Disable screen sharing from System Settings > General > Sharing unless you are already in a session 10. Do not port forward 5900. Use VPN or SSH for remote access if necessary.
There are things about scale that we don’t know. "multiple systems," said the NCSC. That’s not a count. The set doesn't have to be small either. People are often searching for “open 5900” on the internet. Any Mac advertized with the port could have been affected. We don’t have a publicly available phone number.
Nor do we know whether all abused hosts were the same. In the cases observed the results were a Root and a Monero miner. There has been no indication that exploits are being used to install anything other than the miners hitherto. It doesn't say what will be seen, it only says what has been seen.
The bigger risk is new payloads, stolen credentials, more implants or whatever else an attacker with root could drop. That is a possibility, not a fact. "Only miners so far" is not a limit. “Think of it as the reported payload.”
There are also no public facts about who created the Black Hat material, how often it’s used again, or how reliable the exploit is across different versions of macOS. Patch, close 5900, turn off screen sharing when you don't need it. Those gaps don't change the work that needs to be done right now.


A note to those who want to use Screen Sharing
If you are using Screen Sharing to help a teammate or client, you are not allowed to ban it. It has to be less of a habit. System Settings > General > Sharing. Turn it on, so you can share at the beginning of a session. Turn it off when you’re finished. Do not leave it on a computer connected to a network you do not have full control over.


If the other person is not on the last week’s update, get them on it before using the feature again. Fixed versions include macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. As a workaround, don’t connect 5900 to the internet if they can’t update today. Wait a minute. Get a VPN or SSH tunnel.
5900 on the internet is as easy as setting up a port forward you did years ago for a one time session. Check your router and any cloud security group you may have pointed at a mac. Most home routers block that port unless you tell them otherwise. The mode that goes wrong is the exception you wrote but forgot to remove it.