A macOS vulnerability tracked as CVE-2026-65400 is under confirmed active attack: the Netherlands National Cyber Security Centrum reported that attackers have reached root on multiple systems and installed a Monero cryptocurrency miner on each. Apple last week released a patch covering macOS Tahoe, Sequoia, and Sonoma. The fix exists; the question is how many machines have applied it.
The NCSC was specific about what it observed. On affected systems, port 5900, the default port for macOS screen sharing, was internet-accessible. Screen sharing is the built-in feature that lets a remote party view a machine's display and control its keyboard and mouse while the machine is on. Attackers exploited a flaw in the feature's state management, the component responsible for tracking preceding events, user interactions, and system variables. Apple assigned the vulnerability a severity score of 7.1 out of 10.
The read-through is direct: root access plus a miner means an attacker had full control of the affected machine and chose, in these documented cases, to monetize that foothold through Monero mining rather than data theft or a more destructive payload. The miner is the lowest-value use of root. It is also the first documented use, which matters for how organizations read current exposure without dismissing what full control of a machine actually represents.
The counterargument: Apple patched this across three macOS versions simultaneously, and a 7.1 severity score sits below the critical band. The payload seen in confirmed cases is a cryptocurrency miner, not ransomware or a credential harvester. Organizations with functioning patch management and machines that do not expose port 5900 to the public internet are not the NCSC's target audience here. The known cases are serious; they are not a zero-day with no fix available.
On balance, the case for urgency rests on the confirmed root-access incidents. Not the CVE score. The line to watch is whether exploitation stays limited to Monero mining or expands into something more destructive once that root foothold is secured. The risk is unpatched machines with port 5900 open to the internet, and the NCSC has already seen that population in the wild.