An authentication bypass that skips straight to root access, on a service many organisations do not realise they have exposed, is precisely the kind of vulnerability that ages badly once a proof-of-concept goes public. That is what is now happening to CVE-2026-65400.
A validation error, not a missing password
The flaw sits in how macOS Screen Sharing implements Secure Remote Password authentication. A frame-length validation error in the service can cause it to return an outdated success status, effectively telling the connection it succeeded when the credential check never actually passed. The practical result is that an attacker who can reach the Screen Sharing service, which listens on port 5900, does not need a username or password at all. Apple fixed it on August 6 in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.
From a 7.1 to a critical 9.8, and a consistent payload
Apple’s original severity score of 7.1 undersold what was actually possible. CISA rescored the vulnerability to a critical 9.8 after active exploitation confirmed the same outcome in every reported incident: attackers reaching an exposed, unpatched Mac obtained full root access and installed a Monero cryptocurrency miner. The Dutch National Cyber Security Centrum has warned that in-the-wild exploitation is under way, driven by a public proof-of-concept exploit that lowers the skill required to abuse this from “security researcher” to “anyone with the link.” Every case the agency has seen shares one condition: port 5900 reachable from the open internet.
The fix is boring, which is exactly why it gets skipped
The remediation here is not complicated. Update to a patched macOS release, confirm port 5900 is not exposed to the internet, and where remote access to a Mac is genuinely needed, use a VPN or SSH tunnel rather than opening Screen Sharing directly. None of that requires new tooling or budget. What it requires is knowing which Macs in an organisation’s fleet, including ones IT does not actively manage, are still reachable on that port. For businesses running design, media or development teams on Mac hardware, often exactly the users most likely to have remote access enabled for convenience, that inventory gap is the real vulnerability.
If you are not certain which devices in your organisation are still exposed on this or the last dozen patches you meant to roll out, contact Excello Digital. We help European businesses build a patch management and asset inventory process that catches the exposed service before an attacker’s proof-of-concept does.
