Skip to content
Mass Scanning Targets Exposed Vite Development Servers for Cloud Secrets

Mass Scanning Targets Exposed Vite Development Servers for Cloud Secrets

First seen 14 Sep 2026, 17:17 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 17:55 UTC
  • CVE-2026-39364 allows unauthenticated access to sensitive files on Vite servers.
  • F5 detected over 800 attacks and 32,000 raw events in August 2026.
  • Attackers are using extensive wordlists to target AWS and Azure credentials.

In August 2026, a mass-scanning campaign targeted internet-exposed Vite development servers, exploiting CVE-2026-39364 to steal AWS and Azure credentials. The vulnerability allows unauthenticated attackers to bypass file read/access controls by manipulating query parameters in HTTP GET requests. F5's honeynet sensors recorded over 800 attacks and approximately 32,000 raw events linked to this campaign. Attackers utilized extensive wordlists to extract sensitive files, including environment variables and cloud configurations. The vulnerability affects Vite versions 7.1.0 to 7.3.2 and 8.0.5 and was disclosed on April 7, 2026. Most malicious activity originated from the U.S., Belgium, and the Netherlands, with attackers using Google Cloud IP ranges for evasion. Security experts recommend updating Vite servers and blocking suspicious requests to mitigate risks. If unpatched servers are exposed, rotating all secrets is advised.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2005-03-26
CVE-2005-0869 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2017-04-13
CVE-2016-4800 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2017-06-27
CVE-2017-9841 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2018-08-10
CVE-2018-14028 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2018-12-11
CVE-2018-20062 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-03-02
CVE-2021-26855 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-07-14
CVE-2021-34473 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-07-14
CVE-2021-34523 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-09-30
CVE-2022-41082 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2022-09-30
CVE-2022-41040 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV

More articles in this cluster (2)

Following this threat?

Track AWS and CVE-2005-0869 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed