A mass-scanning campaign is exploiting CVE-2026-39364 in exposed Vite development servers to steal cloud credentials, configuration files, and other secrets from AWS and Azure environments. F5 observed hundreds of attacks and thousands of events, with activity linked to traversal tricks, multiple Vite access-control flaws, and source IPs that should be blocklisted. #Vite #CVE-2026-39364 #AWS #Azure
Keypoints
- Attackers are scanning internet-exposed Vite development servers at scale.
- CVE-2026-39364 enables unauthorized file reads by bypassing access controls.
- The campaign targets .env files, AWS credentials, Azure tokens, and Terraform data.
- F5 recorded more than 800 attacks and about 32,000 raw events in one month.
- Defenders should update Vite, restrict port 5173, and rotate exposed secrets.