A critical security vulnerability in Apple macOS is being actively exploited right now, and the attack requires almost nothing from the attacker. No password. No special access. Just a Mac with Screen Sharing turned on and a connection to the internet.
If that describes any Mac in your business or home office, this week's tip requires immediate action.
What the Vulnerability Is
The flaw, identified as CVE-2026-65400, was given a severity score of 9.8 out of 10 — one of the highest possible ratings. It lives in macOS's Screen Sharing component, a built-in feature that allows remote users to view and control a Mac's screen from another device.
The vulnerability is an authentication bypass. In plain terms, it allows an attacker who can reach your Mac over a network to log into the Screen Sharing service without providing valid credentials. There is no password required. No account needed. If the attacker knows the IP address of a Mac with Screen Sharing enabled and can reach it over the internet, they are in.
Once in, attackers have full root-level access to the machine. Root access is the highest level of control possible on any computer. With it, an attacker can install software, read and copy any file, modify system settings, and maintain persistent access long after the initial intrusion.
What Attackers Are Already Doing With It
The Netherlands National Cyber Security Centre has confirmed that active exploitation is already underway. In every confirmed case they have investigated, attackers gained root access to the affected Mac and installed a Monero cryptocurrency miner.
A cryptocurrency miner runs silently in the background, consuming the Mac's processing power and electricity to generate digital currency for the attacker. The victim's machine slows down, electricity bills increase, and hardware experiences accelerated wear, all while the attacker profits.
Researchers scanning the internet found approximately 40,000 Macs with Screen Sharing openly exposed to the internet, with nearly half located in the United States. Among those exposed machines were systems at universities, businesses, and other organizations.
Cryptocurrency mining is the confirmed current activity. That does not mean it is the only possible use of this vulnerability. An attacker with root access to a Mac can do significantly more damage than install a miner if they choose to.
How AI Made This Worse
Security researchers who analyzed these vulnerabilities noted that a working exploit for the two related Screen Sharing flaws was developed using an AI agent in approximately four hours. This is the same pattern appearing across cybersecurity this year: AI is dramatically compressing the time between a vulnerability becoming known and a working attack being built around it. The window between a public disclosure and active exploitation is shrinking, and this case is a clear example of that.
Related Vulnerabilities in the Same Component
CVE-2026-65400 is not the only Screen Sharing flaw patched recently. Three additional vulnerabilities in the same component were addressed in a prior update, including flaws that could allow an attacker to intercept network connections, access sensitive user data, and cause the service to crash. All of these issues exist in the same underlying code.
What Your Team Should Do Right Now
Update every Mac in your environment immediately. Apple released emergency patches specifically addressing these vulnerabilities in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. To check for updates, click the Apple menu, then System Settings, then General, then Software Update. Install any available update immediately.
If any Mac cannot be updated right now, disable Screen Sharing as an interim measure. Go to the Apple menu, then System Settings, then General, then Sharing, and turn off Screen Sharing until the update can be applied. This closes the attack surface until patching is possible.
Check whether Screen Sharing is enabled on any Mac that has it turned on but does not genuinely need it. Many users enable Screen Sharing for a one-time purpose and never turn it off. If it is not actively being used, it should be off.
If your business manages Macs remotely, audit which machines have port 5900 accessible from the internet. That is the port Screen Sharing uses, and any machine with that port openly exposed to the internet while unpatched is at active risk right now.
Review any Mac that has had Screen Sharing enabled and was connected to the internet for unusual behavior, unexplained slowdowns, or high processor usage, which can be signs that a cryptocurrency miner has been installed.
The Bottom Line
A critical macOS vulnerability is being actively exploited today. The attack requires no password. It delivers full control of the machine to the attacker. A patch is available. The only machines at risk are the ones that have not been updated yet. If your team uses Macs, this is not a patch that can wait until next week.

