Hackers are exploiting a macOS Screen Sharing vulnerability to gain root access and install Monero cryptocurrency miners on vulnerable computers [1].
This security breach is significant because it allows remote attackers to bypass authentication and take full control of a system. By installing mining software, attackers can steal computing power for financial gain, while potentially leaving the door open for further malicious activity.
The Netherlands National Cyber Security Centre (NCSC) reported the activity this month [1]. The vulnerability, identified as CVE-2026-65400 [2], affects Mac computers that have the Screen Sharing service exposed to the internet via port 5900 [4].
Attackers use the authentication-bypass flaw to deploy miners for Monero, a privacy-focused cryptocurrency [2]. Once the system is compromised, the attackers gain root access, which is the highest level of permission on a macOS system [3].
There is a discrepancy regarding the severity of the flaw. Initial reports from the Cybersecurity and Infrastructure Security Agency (CISA) listed the CVSS score at 7.1 [3], but other U.S. officials have since rated the severity as 9.8 out of 10 [1].
Apple has released a patch to address the vulnerability. Security experts said users should update their operating systems immediately and avoid exposing port 5900 to the public internet to prevent unauthorized access [4].
“Attackers use the authentication-bypass flaw to deploy miners for Monero”
The exploitation of CVE-2026-65400 highlights a recurring risk for users who expose administrative services directly to the internet. While the current goal of the attackers is cryptocurrency mining, the attainment of root access means the vulnerability could be repurposed for data theft or ransomware. The wide gap in initial severity scores underscores the volatility of vulnerability assessment during active exploitation phases.



