macOS Screen Sharing exploit warning

The Netherlands' NCSC has issued an active warning: a macOS Screen Sharing authentication bypass vulnerability is being exploited in the wild, following the public release of working exploit code. Attackers have been observed using it to deploy Monero cryptomining malware on compromised endpoints.
The detail worth paying attention to here is the exploit code being public. That changes the threat profile considerably - what previously required meaningful technical capability is now accessible to far less sophisticated actors, and opportunistic scanning tends to follow quickly.
If your organisation has macOS in its estate, two immediate questions are worth answering: are your endpoints patched, and is Screen Sharing enabled on machines where it serves no operational purpose? The latter is a common configuration finding we see on assessments - services left enabled by default and never reviewed.
Full reporting via BleepingComputer.
Concerned this affects you?
We can assess your exposure and tell you plainly where you stand.