A security update that went out a month ago as a "just in case" precaution has now turned into a real intrusion affecting multiple computers in the Netherlands. According to Ars Technica, a vulnerability in macOS's Screen Sharing tool has been actively exploited in the wild. The Netherlands National Cyber Security Centrum issued a warning stating they've received reports of "multiple systems" being attacked, with attackers gaining root access in every case and uploading cryptocurrency mining software.

The vulnerability, tracked as CVE-2026-65400, effectively gives attackers the equivalent of physical access to a victim's computer: as long as Screen Sharing is enabled, any attacker on the network can exploit the flaw to log in as any user, without ever needing to know the password. Researcher Calif (@calif_io) published a proof-of-concept (PoC) on X, explaining that they pieced together the details of the vulnerability by reverse-engineering an "unusual" patch Apple issued in macOS 26.6.1.

Apple released patches for Tahoe, Sequoia, and Sonoma several weeks ago. At the time, the vulnerability was still considered theoretical, and the update was treated as a "better safe than sorry" precaution. Now that real-world attacks in the Netherlands have confirmed it's being actively exploited, installing the update has shifted from a recommendation to a necessity.

Beyond updating their systems, users can also disable Screen Sharing directly in System Settings to completely block this attack vector. Security experts further advise that since this vulnerability is exploited through the exposed port 5900, this port should be kept closed regardless of whether Screen Sharing is in use.

It's worth noting that this isn't the only major screen-sharing-related vulnerability to surface recently — Zoom previously had a similar issue, which has since been patched.