On Friday, CISA raised the severity rating of a macOS screen sharing function vulnerability to critical — 9.8 out of 10.
Dutch investigators reported that attackers gained root privileges on internet-connected Mac computers and stealthily installed Monero mining software.
From 7.1 to 9.8 in a Week
When Apple released the patch, CISA scored this bug, tracked as CVE-2026-65400, at 7.1 in the National Vulnerability Database. The agency then revised the score to 9.8, which is close to the top of the CVSS scale.
The Dutch National Cybersecurity Centre took a similar approach. An August 12th update amended its initial advisory, stating that a publicly available proof-of-concept code is in circulation and active abuse has been confirmed.
As of Friday, this vulnerability had not been added to the federal catalog of Known Exploited Vulnerabilities maintained by the Cybersecurity and Infrastructure Security Agency. Apple's own entry in the Dutch agency's CVE registry still had the older 7.1 rating.
The vulnerability relates to how the Screen Sharing function handles authentication. Huntress trac the cause to a flaw in the service's use of the Secure Remote Password protocol, which is used to verify the user before granting access.
Huntress says that in practice, this causes the Mac to believe an outsider has already logged in. The failure occurs before the password check. Resetting or deleting screen sharing passwords does not eliminate this possibility.
"Anyone using Apple’s Screen Sharing feature on any supported version of macOS must immediately install the latest security updates," wrote Huntress researcher Ryan Doud.
Apple released this patch in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 on August 6th.
Tens of Thousands of Rented Mac Computers Are Affected
The NCSC stated that the victims' computers were fully compromised. In every case examined by researchers, the attacker gained access to the system via port 5900, the standard port for screen sharing, which remained open to the internet.
They then obtained root privileges and deployed a Monero cryptocurrency miner ($XMR). The Dutch agency did not disclose the number of affected systems or name a suspect.
The Screen Sharing function is disabled by default. However, it is a standard tool for managing Macs running on "bare metal," meaning physical Apple hardware rented and used in remote data centers, where most of the risk is concentrated.
According to Doud, using the internet scanning tool Censys, he discovered "tens of thousands of potentially vulnerable hosts." Many of these, Huntress claims, are machines rented by the hour from hosting providers.
Cryptopolitan reported on the Reaper malware, which exploits Script Editor to empty wallets, and macOS malfunctions that prompt victims to insert malicious commands into the Terminal.
Cryptojacking, the theft of computing power to obtain cryptocurrency, has long been a hallmark of Monero. Unlike specialized mining rigs, Monero cryptocurrency can be mined on regular CPUs, and transactions are private by default.
The profit from each hacked Mac is low. On Monday, the price estimated roughly 432 $XMR produced by the Monero network per day to be worth approximately $179,000, distributed among all miners. On Monday, $XMR traded at $413.47, up about 0.9% over the previous 24 hours.





