Dutch officials have reported that a high-severity vulnerability in macOS, which allows attackers to execute malicious code, is currently being exploited. The Netherlands National Cyber Security Centrum (NCSC) indicated that there have been instances of active abuse of this vulnerability on multiple systems where port 5900 was accessible from the Internet. In these cases, unauthorized access to the root of the affected systems was noted, along with the installation of a Monero cryptocurrency miner.
The vulnerability, identified as CVE-2026-65400, received a patch from Apple last week for macOS versions Tahoe, Sequoia, and Sonoma. It has a severity rating of 7.1 out of 10 and is linked to a flaw in the macOS screen sharing feature, which enables remote access to view the screen and control the keyboard and mouse. The issue arises from a bug in the state management system, which tracks user interactions and other system states.