Apple's macOS Vulnerability Under Active Exploitation
Dutch authorities have warned of a high-severity macOS vulnerability allowing attackers to execute malicious code. The vulnerability is reportedly under active exploitation.

Dutch officials have issued a warning regarding a critical macOS vulnerability that allows attackers to execute malicious code and gain full control over affected systems. The vulnerability is reportedly under active exploitation.
According to the Netherlands National Cyber Security Centrum (NCSC), active abuse of the vulnerability has been observed on multiple systems where port 5900 was accessible from the internet. In these instances, attackers gained root access and deployed Monero cryptocurrency miners.
The vulnerability, identified as CVE-2026-65400, stems from a flaw in macOS's screen-sharing functionality. This feature normally allows remote users to view and control a computer's keyboard and mouse. Apple released a patch for macOS Tahoe, Sequoia, and Sonoma last week.
The underlying issue is a bug in the system's "state management," which tracks preceding events and user interactions. The vulnerability carries a severity rating of 7.1 out of 10.