Bitrise incident
Public VNC access is temporarily disabled on remote access builds and RDE sessions
Bitrise experienced a minor incident on July 30, 2026 affecting ⚙️ Builds (CI), lasting 31d 21h. The incident has been resolved; the full update timeline is below.
Affected components
⚙️ Builds (CI)
Update timeline
- identified Jul 30, 2026, 03:40 PM UTC
A macOS Screen Sharing (VNC) vulnerability, CVE-2026-43760, is currently being exploited. To protect your machines, we’ve disabled internet-facing access to VNC. SSH is unaffected and remains fully available. We have no evidence that any customer machine was accessed as a result of this vulnerability. This is a proactive measure to reduce exposure. You can connect to the VNC server by tunnelling it over SSH: ssh -L 5900:localhost:5900 $SSH_ADDRESS Then connect to `localhost:5900` with a VNC client.
- resolved Aug 31, 2026, 01:29 PM UTC
This incident has been resolved.