Published Security3 min read
Any Mac with port 5900 open should be treated as breached, not merely unpatched
The Dutch NCSC says attackers used a patched macOS Screen Sharing bypass to take root and drop a Monero miner on multiple systems where TCP 5900 was reachable from the internet.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- The Netherlands' National Cyber Security Centre (NCSC) warned that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.
- The vulnerability lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network using the VNC protocol over TCP port 5900.
- Apple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier releases.
- The flaw allows network-based attackers to gain access without valid credentials.
- An attacker with this access could open applications remotely, access files, change security settings, and perform various other actions.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The Netherlands' National Cyber Security Centre has warned that a macOS authentication bypass is being exploited in the wild after public exploit code appeared [1]. In the cases reported to the agency, the attacker reached root on the affected machine and installed a Monero cryptocurrency miner [7], which moves this from a patch-backlog item to an incident-response question for anyone who left the port open.
The bug is in Screen Sharing, the remote desktop feature built into macOS, which speaks VNC over TCP port 5900 [2]. Apple fixed it as CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier releases [3]. The flaw lets a network-based attacker gain access without valid credentials [4], and from there open applications remotely, read files, change security settings, and take other actions on the host [5].
The NCSC's update is specific about the precondition: "The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet" [8]. It adds that in all of those cases root had been accessed and a Monero miner placed [8].
That combination is what should drive the response. A network-reachable bypass that needs no credentials [4], plus published exploit code [1], plus a fix dated August 6 [3], means every unpatched Mac with 5900 exposed has been trivially reachable for the whole window since the patch shipped [13]. And because the observed intrusions ended in root [7], with the underlying access allowing security settings to be changed [5], installing the update closes the door but does not undo anything already done behind it [14]. Patch, then look for what is running.
The remediation itself is unremarkable. Three release lines carry the fix: macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 [9][15]. Apple's change improves state management so that credential validation is enforced correctly and rogue authentication attempts are rejected [10]. Where updating is not immediately possible, Screen Sharing can be turned off in System Settings under General, then Sharing, then Screen Sharing, if it is not needed [11].
What the NCSC has not published matters for how much weight to put on the miner. The agency has not shared details of the reported attacks, when they started, whether the activity extends beyond cryptocurrency mining, or how many systems were affected [12]. A miner is the cheapest thing to do with root, and it is also the easiest thing to find; absent a timeline or a victim count, treating coin mining as the ceiling of attacker intent is an assumption, not a finding [12].
Watch for an NCSC update that puts numbers and dates on the intrusions, and for any report of payloads other than the miner on the same hosts [12]. On your own estate, the useful task this week is not a patch report but an exposure report: which Macs have answered on 5900 from outside since early August [2][3], and what has been running on them as root since [7].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The Netherlands' National Cyber Security Centre (NCSC) warned that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.
- [2]
The vulnerability lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network using the VNC protocol over TCP port 5900.
ReportedView cited source - [3]
Apple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier releases.
ReportedView cited source - [4]
The flaw allows network-based attackers to gain access without valid credentials.
ReportedView cited source - [5]
An attacker with this access could open applications remotely, access files, change security settings, and perform various other actions.
ReportedView cited source - [6]
In an update to its initial advisory, the Dutch agency said it received a report indicating the vulnerability is being exploited in the wild in attacks where port 5900 is exposed to the internet.
Sources & coverage · 4 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comBill ToulasAug 14Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
- bleepingcomputer.com6d agoHackers exploit macOS Screen Sharing flaw to deploy Monero miner
- securityweek.comIonut Arghire6d ago



