Exposed Vite servers are being probed for AWS and Azure credentials

Summary

Attackers are actively scanning exposed Vite servers for sensitive data, including AWS and Azure credentials, and infrastructure configuration files. This activity targets a recently disclosed vulnerability, CVE-2026-39364, which allows unauthenticated attackers to bypass file-access restrictions on Vite servers. The increased scanning indicates a new threat vector for software developers.

IFF Assessment

FOE

The article details active exploitation of a vulnerability that allows attackers to gain access to sensitive cloud credentials and infrastructure configurations, posing a direct threat to defenders.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: May 03, 2022. Known ransomware use: Unknown.

Defender Context

Developers using Vite should ensure their servers are not exposed publicly and are properly configured to prevent unauthorized access to sensitive files. Defenders should be aware of this emerging threat and monitor for attempts to exploit CVE-2026-39364, particularly in environments hosting development or build servers.

Read Full Story →