CVE Tools

Hackers target exposed Vite dev servers to steal AWS, Azure secrets

BleepingComputerBy Bill Toulas

Reported exploitedVite

Our summary

Attackers are actively exploiting a high-severity vulnerability in Vite development servers to extract sensitive cloud credentials and configuration files from AWS and Azure environments. The campaign targets unpatched instances of versions 7.1.0 through 7.3.2, as well as the 8.x branch prior to 8.0.5, using CVE-2026-39364 to bypass file access controls.

F5 detected over 800 distinct attack attempts over one month, noting that adversaries leverage specific query parameters to read protected files in plaintext. Upon successful access, attackers systematically probe for environment variables, Terraform states, and service account tokens. Organizations running publicly exposed Vite servers should update to the latest version and rotate any potentially compromised secrets.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store