A critical authentication flaw in macOS’s built-in Screen Sharing service, tracked as CVE-2026-65400, is being actively exploited on internet-exposed Macs to install cryptocurrency mining software. The Netherlands’ National Cyber Security Centre confirmed multiple compromised devices, and security firm Huntress estimates tens of thousands of Macs were potentially exposed — many of them machines rented by the hour from hosting providers rather than office desktops. The US Cybersecurity and Infrastructure Security Agency has rated the flaw 9.8 out of 10.

Apple has already shipped emergency patches in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. If any Mac in your business hasn’t installed one of those updates yet, that’s the first thing to fix today, not this week.

Why this one is worse than it sounds

What makes CVE-2026-65400 notable isn’t just the severity score, it’s how little skill it takes to exploit. Researchers found no memory corruption, no exploit trickery, no race condition to win — just a logic error that lets a couple of correctly ordered network packets walk straight past authentication on the Screen Sharing service. An attacker who reaches an exposed Mac gets full remote control, no valid credentials required.

The payload seen so far is “only” a Monero cryptocurrency miner — annoying, resource-draining, and a clear sign the machine is compromised, but not immediately destructive. That’s the current attack, not the ceiling of what this flaw allows. Full unauthenticated remote access to a machine is equally useful for data theft, deploying ransomware, or pivoting further into a network, and it would be a mistake to read “it’s just a cryptominer” as “this isn’t serious.”

What to check today

Patch every Mac in your business, including ones you might not think of as “servers.” This includes any Mac mini used for CI/CD, build pipelines, or as a lightweight always-on machine, since those are exactly the kind of internet-facing, unattended devices most exposed to this flaw.

Check whether Screen Sharing is actually exposed to the internet on any device. Screen Sharing is meant for local network or VPN-based remote access, not direct internet exposure. If any Mac has a router port forward or cloud firewall rule opening port 5900 to the wider internet, close it — that’s the exact exposure attackers are scanning for.

If you rent Mac infrastructure by the hour from a hosting provider, for iOS builds, testing, or CI, check with that provider directly on patch status. Huntress specifically flagged rented, hourly-billed Mac instances as a heavily affected category, and you may not control the underlying patch cadence yourself.

If a compromise like this did land on your business — or you want continuous visibility into whether any of your infrastructure has already been targeted — KeepSafe monitors for exactly this kind of incident so you’re not finding out from a slow machine or a spiked electricity bill. And if you’re not sure your current network setup would actually stop something like this reaching an exposed device, CoolCoding can review your configuration properly.

The takeaway

This is a rare case where the fix is genuinely simple — patch, and close any accidental internet exposure of a remote-access service — but the flaw itself is about as bad as they come: unauthenticated, full remote control, on a platform many UK SMEs assume is safer by default than it actually is. Check every Mac your business touches today, not just the ones sitting on desks.