Critical macOS Flaw Exploited in Cryptomining Attacks Triggers Emergency Apple Updates
CVSS 9.8 Authentication Bypass Allows Root Execution Over Port 5900
Cybercriminals are actively exploiting a critical 9.8-severity authentication vulnerability in Apple macOS to remotely breach Mac computers without valid credentials, prompting emergency operating system updates from Cupertino. The vulnerability, designated as CVE-2026-65400, allows unauthorized remote entry into systems that have Apple’s screen sharing feature turned on.
The security flaw stems from insufficient state management during the operating system’s authentication process. Under normal execution, macOS rejects remote connection requests that lack valid administrative credentials. However, CVE-2026-65400 allows attackers to bypass credential validation entirely when negotiating connection requests over local or public networks.
The flaw affects macOS Sequoia, Sonoma, and Tahoe, and Apple closed it off in versions 15.7.9, 14.8.9, and 26.6.1, respectively. Unknown criminals have been exploiting the PoC to break into “multiple” Mac systems through port 5900, which is open when the Screen Sharing feature is set to on.
TCP port 5900 handles network traffic for macOS Screen Sharing using Virtual Network Computing protocols. Security analysis published by the Netherlands’ National Cyber Security Centre (NCSC-NL) rated the flaw at 9.8 on the Common Vulnerability Scoring System scale, citing a remote network attack vector requiring zero elevated permissions or user interaction.
The cyber-criminals have allegedly abused CVE-2026-65400 to gain root access to macOS and install a Monero cryptomining trojan on vulnerable systems. Most likely, things could have turned much worse: working root access means “game over” for any native security protections, plus the ability to essentially implant any kind of malicious code on the compromised system.
The zero-day vulnerability was discovered by Alfredo Pesoli, co-founder and chief executive officer of cybersecurity firm Bynario. Pesoli uncovered the authentication bypass using Atlas, an automated security analysis solution developed by Bynario to detect high-impact software logic flaws.
Apple confirmed the fix across individual support bulletins for macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1, giving credit to Pesoli for reporting the issue. Technical details and patch downloads are available through Apple Security Updates. NCSC-NL confirmed that evidence of a functional proof-of-concept exploit was detected spreading across public network channels one week before Apple issued the patch.









