CISA upgraded the severity score for a macOS Screen Sharing vulnerability to a critical 9.8 out of 10 on Friday.
Dutch investigators have reported attackers gaining root control of internet-exposed Macs and quietly loading Monero mining software.
From 7.1 to 9.8 in a week
When Apple shipped its fix, CISA listed the bug, tracked as CVE-2026-65400, at 7.1 in the National Vulnerability Database. The agency changed it to 9.8, near the top of the CVSS scale.
The Netherlandsβ National Cyber Security Centre took a similar approach. An update on August 12 revised an initial advisory to say that public proof-of-concept code was in circulation and that active abuse had been confirmed.
As of Friday, the flaw had not been included in a federal catalog of known attacked vulnerabilities maintained by the Cybersecurity and Infrastructure Security Agency. Appleβs own CVE record with the Dutch agency still had the older 7.1 rating.
The vulnerability is due to the way Screen Sharing handles authentication. The security company Huntress traced it to a flaw in the serviceβs use of Secure Remote Password, the protocol used to verify a userβs identity before granting access.
Huntress says the practical effect is that the Mac thinks the outsider has signed in already. The failure occurs prior to any password verification. Resetting or deleting Screen Sharing passwords doesnβt shut the door.
βAnybody who leverages Appleβs Screen Sharing functionality on any supported macOS version needs to apply the most recent security updates immediately,β Huntress researcher Ryan Dowd wrote.
Apple delivered that fix in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 on August 6.
Tens of thousands of rented Macs in range
The NCSC found that victim machines were totally compromised. In each case examined by the researchers, the attacker accessed the system via port 5900, the default Screen Sharing port that remained exposed to the internet.
They then escalated to root privileges and deployed a Monero (XMR) cryptocurrency miner. The Dutch agency did not give the number of systems affected or name a suspect.
Screen Sharing is disabled by default. However, it is a standard tool for working with βbare-metalβ Macs, which are physical Apple hardware rented and run inside remote data centers, where much of the exposure is concentrated.
With the internet-scanning tool Censys, Dowd said he found βtens of thousands of potentially vulnerable hosts.β Many, Huntress says, are machines rented by the hour from hosting services.
Cryptopolitan reported on the Reaper malware that hijacks Script Editor to drain wallets and fake macOS troubleshooting posts that lead victims to paste malicious Terminal commands.
Cryptojacking, stealing computing power to turn into coins, has long been a Monero activity. Unlike specialist rigs, Monero coins can be mined on normal CPUs, and its transactions are private by design.
The return per hijacked Mac is small. Mondayβs price valued the about 432 XMR a day minted by the Monero network at ~$179,000, distributed across all the miners. XMR was trading at $413.47 on Monday, up about 0.9% over 24 hours.
The smartest crypto minds already read our newsletter. Want in? Join them.


















English (US)