Hackers are actively exploiting a macOS Screen Sharing vulnerability to obtain root access and deploy a Monero cryptocurrency miner, according to BleepingComputer, which cites an updated warning from the Netherlands’ National Cyber Security Centre. The flaw is tracked as CVE-2026-65400 and sits in macOS Screen Sharing, Apple’s built-in remote desktop capability. BleepingComputer reports that the feature uses the Virtual Network Computing protocol over TCP port 5900, making exposure of that port a key risk factor in the incidents described by the Dutch agency. BleepingComputer reports that Apple issued fixes on August 6 for CVE-2026-65400, citing macOS Tahoe 26.6.1. The issue is an authentication bypass: a network-based attacker can gain access without valid credentials. Once inside, the attacker could remotely open applications, access files, change security settings, and take other actions on the system. The NCSC update said it had received a notification that active abuse had been seen on multiple systems where port 5900 was accessible from the internet. In each reported case described by the agency, root had been accessed on the affected Mac and a Monero miner had been installed. That pattern makes the immediate observed payload financially motivated rather than destructive, but the access described is broader than cryptomining alone. Root access on a remotely reachable Mac gives an attacker significant control over the endpoint; the Dutch agency has not said whether the activity goes beyond mining. The available reporting leaves several operational details unresolved. BleepingComputer says the Dutch agency has not disclosed when the attacks started, how many systems were affected, or whether the campaign is limited to cryptocurrency mining. The practical mitigation is straightforward. Organizations should apply Apple’s fix where possible. Where systems cannot be updated immediately, BleepingComputer reports that users can disable Screen Sharing through System Settings if the feature is not needed. Who benefits: Administrators who have already patched or disabled unnecessary Screen Sharing reduce the attack surface described in the NCSC warning. Attackers benefit when Screen Sharing is left internet-accessible on unpatched systems. Who's exposed: The clearest exposure is macOS systems with Screen Sharing reachable from the internet on TCP port 5900 and without the relevant Apple fix. The provided reporting does not quantify how many such systems have been affected.