Critical macOS Screen Sharing Bug Actively Exploited to Install Crypto Miners
The Netherlands National Cyber Security Centre (NCSC) has issued a warning that a recently patched macOS vulnerability is being actively exploited in real-world attacks. Tracked as CVE-2026-65400 and rated 9.8 out of 10 in severity, the flaw affects the Screen Sharing component of macOS and allows an attacker already on the same network to bypass authentication controls.
Attackers are reportedly using this vulnerability to gain unauthorised access to Macs that have Screen Sharing exposed to the internet, then installing a Monero cryptocurrency miner. While cryptomining malware may seem less dangerous than ransomware or data theft, its presence indicates a broader security failure: any attacker able to install mining software could just as easily install more damaging tools, steal data, or move deeper into a business network.
Apple has already released a patch for this vulnerability, meaning businesses using Macs are protected simply by keeping their systems up to date. However, any organisation that has delayed applying recent macOS updates, or that has Screen Sharing enabled and accessible from the internet, remains at risk. Small businesses using Macs for daily operations should treat this as a reminder that remote access features, if left exposed, are a common target for opportunistic attackers.