Dutch authorities warn that a high-severity macOS vulnerability is being actively exploited in the wild. The Netherlands National Cyber Security Centre (NCSC) says it received reports of abuse on multiple systems reachable from the internet via port 5900. In the observed cases, attackers gain root access and deploy a Monero cryptocurrency miner.
The flaw is tracked as CVE-2026-65400 and is linked to macOS screen sharing. Officials and security reporting say the bug allows a remote party to view a device’s screen and control the keyboard and mouse when the machine is on, due to a problem in how the feature manages internal state. Apple released a patch last week for macOS Tahoe, Sequoia, and Sonoma, and disclosed that the issue “may” allow passwordless access, a cautious wording that has been echoed by how other vendors sometimes describe risk.
Outlets differ mainly in emphasis: Slashdot focuses on the exploitation details, including how port 5900 exposure occurs when screen sharing is enabled and the typical mitigations (closing the port, using VPN/SSH tunneling). Ars Technica emphasizes the core impact—that remote hackers can log in without a password—and ties it to the active exploitation described by the NCSC.