Dutch officials report root access and Monero miners on Macs with port 5900 open to the internet. Sonoma, Sequoia and Tahoe all need the update Apple shipped as an important security fix.
Perspective Coverage
5 publishers
- Builder
- Builder 22%
- Operator
- Operator 70%
- Investor
- Investor 8%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence68
The Dutch NCSC says CVE-2026-65400 was abused within two weeks of Apple's fix, with root access and Monero miners in every reported case. Patching closes the door; it does not evict anyone.
Perspective Coverage
6 publishers
- Builder
- Builder 22%
- Operator
- Operator 72%
- Investor
- Investor 6%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence62
Apple's September 14 releases close 273 unique vulnerabilities across ten advisories, with no exploitation reported. Fleet managers have to pick which lane to patch on, and the 26.7 build leaves out about 56 of the fixes that ship in iOS 27.
Reality
- Evidence74
- Adoption55
- Hype gap+18
- Incentives40
- Confidence72
CVE-2026-65400 let an attacker on the network authenticate to Screen Sharing without valid credentials. Apple's note names macOS Tahoe only, so treat wider backport claims as unconfirmed.
Publishers:support.apple.com
Reality
- Evidence76
- Adoption28
- Hype gap−4
- Incentives58
- Confidence68
Huntress says a public proof of concept needs only an IP address to pull any file off unpatched Macs, driving a helper process that carries Full Disk Access.
Reality
- Evidence68
- Adoption42
- Hype gap+12
- Incentives62
- Confidence55
An authentication state flaw lets anyone who reaches TCP/5900 skip credentials entirely. Multiple cases reported to NCSC-NL ended in root and a Monero miner.
Reality
- Evidence34
- Adoption31
- Hype gap+18
- Incentives24
- Confidence41