Exposed Vite servers are being probed for AWS and Azure credentials
Summary
Attackers are actively scanning exposed Vite servers for sensitive data, including AWS and Azure credentials, and infrastructure configuration files. This activity targets a recently disclosed vulnerability, CVE-2026-39364, which allows unauthenticated attackers to bypass file-access restrictions on Vite servers. The increased scanning indicates a new threat vector for software developers.
IFF Assessment
The article details active exploitation of a vulnerability that allows attackers to gain access to sensitive cloud credentials and infrastructure configurations, posing a direct threat to defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: May 03, 2022. Known ransomware use: Unknown.
Defender Context
Developers using Vite should ensure their servers are not exposed publicly and are properly configured to prevent unauthorized access to sensitive files. Defenders should be aware of this emerging threat and monitor for attempts to exploit CVE-2026-39364, particularly in environments hosting development or build servers.