Welcome to MacStadium's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation.
If you need to request that our GRC team complete a custom questionnaire or online assessment as part of your vendor evaluation process, please submit the document or URL through this trust center after requesting portal access above and then create security@macstadium.com as the user account in your vendor platform. Please be advised that email requests will not be fulfilled without a registered account and submission of your request through the trust center portal.
Trust Center Updates
MacStadium CVE-2026-65400 Investigation Summary
Investigation Overview
As Apple released the latest macOS updates on August 6th and published information on CVE-2026-65400 to National Vulnerability Database, the MacStadium Security Operations team has been conducting an ongoing investigation to determine any potential impact to our internal corporate systems that may affect our clients.
At this time, MacStadium, in conjunction with our Rapid7 MDR SOC team, have completed threat hunt activities and no indicators of compromise have been detected in our internal corporate systems. The security controls implemented within our corporate environments have been effective in mitigating exploitation risks. We continue to monitor our systems closely and will provide notification to clients in the event that anything changes. IoC’s can be shared with clients upon request.
Mitigating Security Controls in Place on MacStadium Corporate Devices
MacStadium system hardening procedures for all corporate macOS laptops and desktops have Screen Sharing disabled by default. MDM profiles and just-in-time privileged access escalation controls are also in place to prevent enablement without oversight. Continuous vulnerability scanning, advanced endpoint protection and File Integrity Monitoring are implemented as additional protections. The latest macOS updates released by Apple on August 6th have been pushed and successfully installed to a patched level for all corporate devices.
Detection in Customer Bare Metal Infrastructure Environments
The MacStadium customer support team has had a number of clients open tickets indicating possible exploitation of their dedicated host infrastructure; however, MacStadium does not have access to client operating systems to be able to perform forensic analysis or confirm exploitation of this specific CVE.
Many of these clients appeared to be using Screen Sharing on a public IP address without a firewall or endpoint protection and had not yet applied the latest macOS updates. Our recommendation for those clients is to wipe the machine and reinstall a patched version of macOS as indicated in our recent document update regarding this vulnerability. We also highly recommend the use of a firewall and VPN encryption to help protect network traffic from exploit.
As part of the MacStadium Shared Responsibility Model, clients are responsible for patching OS and application vulnerabilities within their dedicated private cloud infrastructure environment, for maintaining appropriate firewall rules and policies, for backup and recovery of data, and for monitoring of any malicious system or network activity.
Our goal is to assist our customers in performing their own incident response activities however we can. To that end, we did apply a block of all inbound port 5900 traffic from the Internet on Monday August 10th at 11:50am ET in the core routers in each of our data centers intended to prevent any further potential for unauthorized access via this exploit and give our clients time to patch their systems appropriately. The support team provided clients with instructions on how to apply mitigating controls and securely access their hosts using SSH tunneling to perform forensic analysis and apply patches. We also modified the default Screen Sharing port that is configured for all newly deployed infrastructure provisioned for our customers. It should be noted that these measures do not completely prevent exploitation of this CVE and customers are advised to take appropriate measures to further protect their systems, most importantly, updating MacOS to a version that is patched for this exploit..
The Orka Host Operating System
MacStadium manages the host operating system for all Orka infrastructure nodes. Customers manage their guest virtual image operating systems that they deploy on the host along with the security policy on the dedicated firewall.
TCP/5900 running on the Orka host is the node’s own macOS Screen Sharing service. We enable it deliberately: it’s what we use to run node upgrades and to troubleshoot the host directly. Screen Sharing for client VMs forwards to a different port as a separate service. Orka host nodes are currently running a version of macOS that is unpatched.
What we’re doing about it. Validating the patched macOS builds against Orka is a priority task for us. We qualify host builds through a formal process before rolling them to production clusters. We do this to ensure stability for customers and ensure there is no impact at deployment. Apple’s fixed builds are recent and haven’t cleared validation yet. Once validation lands: every newly deployed and reprovisioned node will run a patched build, and existing clusters can be upgraded to it on request.
On current exposure. Orka nodes have never been reachable from the public Internet on any port, unless specifically configured. Orka’s architecture for our MacStadium hosted clusters implements a firewall which serves as a layer of protection for Orka nodes. The cluster sits behind a Cisco firewall gating all Internet traffic, with node access only over VPN. The block on port 5900 at our datacenter’s edges is an additional layer of protection for our customers, but not one Orka nodes depend on. Since exploiting this CVE requires reachability to the Screen Sharing service and no public Internet path to it exists or has existed for an Orka environment, our assessment is that client’s host nodes have not had any public exposure at any point in the exploit’s affected window or prior. at any point in the affected window. We’ve found no evidence of exploitation or unauthorized access to client environments.
Residual risk. Those are perimeter controls and they don’t filter east-west traffic inside a customer’s own network segment. A client on your VPN can reach 5900 on the nodes. The exposure is bounded to an actor already authenticated to a customer’s VPN or one who’s moved laterally into that segment, a population a customer’s own access controls define. Materially smaller than an Internet-reachable host. It closes when the nodes move to a patched build.
On the guest side, a customer’s VM images are theirs to patch or rebuild on whatever cadence suits them. We have provided a patched VM image of Tahoe for convenience (here). Disabling Screen Sharing in the VM is entirely a customer’s call. If you want screen sharing to a VM without an open port, an SSH tunnel over your assigned SSH port is what we’d recommend.
If you have questions or need additional information, please reach out to your MacStadium account manager, open a support ticket at https://portal.macstadium.com, or send an email to security@macstadium.com.
Notice of Updates to MacStadium Subprocessors
MacStadium is committed to protecting the security and privacy of the personal data you entrust with us. To continue delivering the highest quality of service, we periodically update the third-party vendors and service providers ("sub-processors") that assist us in providing MacStadium services. These sub-processors help us to deliver product features, improve customer support, maintain critical infrastructure, and enhance service reliability.
In accordance with our contractual obligations, this notice is to inform you of the addition of the following subprocessor, with the intent to commence on September 20th, 2026:
Sub-processor: Plain
Headquarters Location: London, England, United Kingdom
Location of hosting: AWS eu-west-2 London, England
Service Provided: customer support trouble ticketing and management system
Data Handled: Customer support ticket information, including contact information and customer content processed as part of troubleshooting issues.
To learn more about Plain and their commitment to security and data privacy by visiting https://help.plain.com/article/security
Effective Date: September 20th, 2026
Reason for Use: MacStadium Technical Support is implementing Anthropic Claude for managing customer chatbot inquiries and support requests.
What You Need to Do
No action is required on your part if you agree to these updates. However, if you wish to object to our use of this new MacStadium sub-processor for reasons related to data protection, please send an email to privacy@macstadium.com within thirty (30) days of this notification with both:
The subject “Sub-processor Objection”, and
The grounds for the objection.
Please note that MacStadium has undertaken appropriate due diligence to ensure any requirements of MacStadium as it relates to its use of subprocessors has been considered and satisfied. Please also note that this subprocessor update does not result in any changes to the personal data types or categories referenced in any applicable Data Processing Agreement (DPA) or similar such agreement between you and MacStadium.
Additionally, the following list of former subprocessor vendors are no longer being utilized by MacStadium and have been removed from service:
ZenDesk
Appropriate measures have been taken to delete all personal information that was previously processed or stored by this vendor in accordance with our contractual obligations.
You may view the full list of MacStadium’s subprocessors in the MacStadium Trust Center by visiting https://trust.macstadium.com/
Thank you for trusting MacStadium to manage your data with the highest standards of security and compliance.
The MacStadium Privacy Team
privacy@macstadium.com
Notice of Updates to Privacy Policy
MacStadium has updated our Privacy Policy, effective 08/07/2026. These updates strengthen your privacy rights and reflect current legal requirements. We encourage you to review the full policy here: https://macstadium.com/privacy-policy
Summary of key updates:
-
Legal bases for processing (GDPR/UK GDPR): We've clarified the legal bases we rely on to process your personal data, and added specific provisions for handling special category data where applicable.
-
Opt-out preference signals (GPC): We now recognize and honor Global Privacy Control (GPC) signals as a valid method of opting out of the sale/sharing of personal information, in addition to other opt-out methods.
-
Right to lodge a complaint: If you're in the EU/UK, we've clarified your right to lodge a complaint with your local supervisory authority if you believe your data protection rights have been violated.
-
CCPA response timing: We've updated the timeframes in which we respond to consumer requests under the California Consumer Privacy Act (CCPA), and clarified your right to limit the use of sensitive personal information.
-
International data transfers: We've added detail on the safeguards we use when transferring personal data internationally (e.g., Standard Contractual Clauses or other approved mechanisms).
-
Cookie consent: We've updated our cookie practices and consent mechanisms to give you clearer choices over non-essential cookies and tracking technologies.
-
Notice of future changes: We've clarified how we'll notify you of material changes to this policy going forward.
What this means for you:
No action is required on your part. Your continued use of MacStadium’s products/services after 08/07/2026 constitutes acceptance of the updated Privacy Policy.
Have questions?
If you have questions about these changes or want to exercise any of your privacy rights, contact us at privacy@macstadium.com or visit https://macstadium.com/privacy-policy-opt-out
Thank you for trusting us with your information.
Best regards,
MacStadium Data Privacy Team
3340 Peachtree Rd NE, Suite 2330, Atlanta, GA 30326
React2Shell (CVE-2025-55182)
MacStadium received initial intelligence of a proof-of-concept on this threat Thursday December 4th at 12:00 noon ET and began conducting internal vulnerability scans and threat hunting activities in coordination with our SOC team. No unpatched systems or indicators of compromise were detected in any of our infrastructure environments at that time. Internal and external vulnerability scans were executed again over the weekend and confirmed that no vulnerable instances of Next.js exist within MacStadium’s infrastructure environment.
MacStadium's devops team has confirmed that there were no vulnerable instances of Next.js within any of our software development projects. As part of our CI/CD processes, we have branch protection rules that utilize Renovate to update libraries and Trivey to identify vulnerabilities in the enforcement of our zero-cve policy for all software releases.
Our GRC team has also been engaging with our third-party critical vendors and sub processors to inquire about their potential exposure to the threat and no potential for impact has been identified at this time. We continue to monitor responses from our Nth party vendors for any additional risk exposure and will provide any updates as they are received.
ISO 27001 Annual Report
MacStadium's latest ISO 27001/27017/27018 second surveillance audit report is now available for review and download. We are pleased to announce that no major or minor control nonconformities were identified in the review period, reinforcing a high level of confidence in MacStadium's processes and security controls designed to protect our client's systems, users, and data.
Please reach out to security@macstadium.com with any questions or to initiate a vendor risk analysis.
The MacStadium Security & Compliance Team








