Apple has patched a critical macOS Screen Sharing vulnerability that attackers have been exploiting to gain root access on internet-facing Macs and install Monero mining software. The Dutch National Cyber Security Centre (NCSC) confirmed active exploitation in an updated advisory on Aug. 12, according to crypto.news.

The vulnerability, tracked as CVE-2026-65400, was patched by Apple on Aug. 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The company described it as an authentication flaw caused by improper state management that could allow an attacker on the network to access Screen Sharing without valid credentials.

Security firm Huntress analyzed the flaw and found it affects the Secure Remote Password authentication process used by macOS Screen Sharing. The analysis showed an attacker could cause the service to treat an unauthenticated connection as authenticated and obtain privileged access. Because exploitation occurs before normal authentication, Huntress said changing a Screen Sharing password, disabling legacy VNC authentication, or removing authorized user accounts does not address the vulnerability. The recommended fix is installing Apple's latest security update or disabling Screen Sharing until the system can be patched.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has upgraded the severity score to 9.8 critical, up from an earlier 7.1 assessment. The National Vulnerability Database shows CISA upgraded the scoring on Aug. 14.

Huntress researcher Ryan Dowd said a Censys search identified "tens of thousands of potentially vulnerable hosts." That estimate covers Macs that appeared exposed to the internet and should not be interpreted as confirmed compromises. The risk is particularly relevant to hosted bare-metal Macs, including Mac minis rented for remote workloads. Some hosting environments expose Screen Sharing services on newly provisioned machines, increasing the attack surface when systems have not yet received Apple's Aug. 6 patches.

The Dutch cases involved cryptojacking rather than theft of wallet credentials. Attackers used the compromised Macs' computing resources to mine Monero after obtaining root control. The NCSC has not disclosed the mining software, pool addresses, attacker wallets, or resulting XMR proceeds. Monero has repeatedly appeared in cryptojacking campaigns because it can be mined using general-purpose computing hardware.

As crypto.news previously reported, a Darktrace investigation found malware quietly deploying cryptocurrency mining software after attackers gained access to Windows systems. Apple devices have also faced other crypto-related malware campaigns, including North Korean hackers targeting macOS users with malware aimed at crypto companies using fake meetings and malicious software updates.

Monero (XMR) traded at around $414 at press time, indicating less than 1% increase in the past 24 hours and almost 5% in the past 7 days, according to crypto.news market data.

The immediate priority is patching Macs running vulnerable versions of Sonoma, Sequoia, and Tahoe. Systems exposed directly to the internet through Screen Sharing face the clearest documented risk, although Huntress recommends updating Macs even when administrators believe the service is disabled. The Dutch NCSC has confirmed exploitation but has not attributed the campaign or published indicators identifying the Monero mining infrastructure. Further disclosures from incident responders could clarify how widespread the attacks became before Apple's Aug. 6 fix.