Bleepingcomputer Mass Scanning Targets Exposed Vite Development Servers for Cloud Secrets
Article Content
- •CVE-2026-39364 allows unauthenticated access to sensitive files on Vite servers.
- •F5 detected over 800 attacks and 32,000 raw events in August 2026.
- •Attackers are using extensive wordlists to target AWS and Azure credentials.
In August 2026, a mass-scanning campaign targeted internet-exposed Vite development servers, exploiting CVE-2026-39364 to steal AWS and Azure credentials. The vulnerability allows unauthenticated attackers to bypass file read/access controls by manipulating query parameters in HTTP GET requests. F5's honeynet sensors recorded over 800 attacks and approximately 32,000 raw events linked to this campaign. Attackers utilized extensive wordlists to extract sensitive files, including environment variables and cloud configurations. The vulnerability affects Vite versions 7.1.0 to 7.3.2 and 8.0.5 and was disclosed on April 7, 2026. Most malicious activity originated from the U.S., Belgium, and the Netherlands, with attackers using Google Cloud IP ranges for evasion. Security experts recommend updating Vite servers and blocking suspicious requests to mitigate risks. If unpatched servers are exposed, rotating all secrets is advised.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track AWS and CVE-2005-0869 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…