Attackers are exploiting a critical macOS Screen Sharing vulnerability (CVE-2026-65400) to gain root access and deploy Monero cryptocurrency miners on unpatched Macs. The Netherlands’ National Cyber Security Centre confirmed active exploitation this week after public exploit code surfaced online.
The flaw lets an attacker on the network bypass authentication entirely — no credentials needed. Once in, they get root access. In every reported case so far, the attackers installed a crypto miner that silently chews through CPU resources in the background.
Who’s at risk: Any Mac running macOS Tahoe, Sequoia, or Sonoma with Screen Sharing enabled and port 5900 reachable. We see this more often than you’d expect in Australian SMBs — Screen Sharing is routinely left on for remote IT support, and because it’s a Mac, patching gets treated as less urgent than Windows updates. That assumption is exactly what attackers are counting on.
What to do right now:
Update to macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 — Apple patched this on 6 August. If you can’t update immediately, disable Screen Sharing in System Settings → General → Sharing. Either way, check that port 5900 isn’t exposed to the internet. It shouldn’t be.
If your business relies on Macs and you’re not sure whether Screen Sharing is exposed, get in touch with All IT Services. We can audit your Mac fleet and lock down remote access properly — without losing the convenience of remote support.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
