Bitrise disabled public VNC access on remote access builds and RDE sessions as a proactive response to macOS Screen Sharing vulnerability CVE-2026-43760, with no evidence of any customer machines being compromised. The incident lasted approximately 32 days before being resolved on August 31, 2026. SSH access remained fully available throughout, and users could still reach VNC by tunneling it over SSH as a workaround.
Trusted by 1,000+ teams
Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.
This incident has been resolved.
A macOS Screen Sharing (VNC) vulnerability, CVE-2026-43760, has been announced. To protect your machines, we’ve disabled internet-facing access to VNC. SSH is unaffected and remains fully available.
We have no evidence that any customer machine was accessed as a result of this vulnerability. This is a proactive measure to reduce exposure.
You can connect to the VNC server by tunnelling it over SSH:
ssh -L 5900:localhost:5900 $SSH_ADDRESS
Then connect to `localhost:5900` with a VNC client.
With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.
Start free trialNo credit card required · Cancel anytime · 6320 services available
Integrations with