PLATFORMS Signal 419
Mass scans exploit Vite CVE-2026-39364 to harvest cloud credentials from exposed dev servers
A mass-scanning campaign exploits CVE-2026-39364 to pull environment files, cloud credentials, and Terraform state from exposed Vite development servers.
Development servers that are publicly reachable can leak secrets that application code needs at build or runtime. Patching the vulnerability does not invalidate credentials already exposed, so teams must rotate any secrets accessible from a vulnerable server and restrict network access to port 5173.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The campaign exploits CVE-2026-39364, affecting Vite 7.1.0 through 7.3.2 and 8.x before 8.0.5.
F5 honeypots recorded over 800 attacks and roughly 32,000 raw events in one month.
Defenders should update Vite, block public access to port 5173, and rotate credentials that may have been exposed.
THE CLUSTER
↗