A large-scale campaign exploited CVE-2026-39364 to extract sensitive files from internet-exposed Vite development servers. The CVSS 8.2 file-disclosure flaw affects Vite versions 7.1.0–7.3.1 and 8.0.0–8.0.4, allowing unauthenticated requests to bypass server.fs.deny restrictions via crafted @fs paths and query parameters. F5 honeypots logged 807 session-grouped attacks and about 32,000 raw events during August, a substantial increase over preceding Vite-related activity.
Attackers sought .env files, AWS credentials and configuration, Azure profiles, Terraform and Serverless Framework state artifacts, and Linux process and system data. Requests used encoded path traversal, impersonated major crawler and AI-bot user agents, forged forwarding headers, and often originated from Google Cloud address space. Organizations should upgrade to Vite 7.3.2, 8.0.5, or a later supported release; remove development servers from public exposure; investigate logs and cloud audit trails; and rotate any credentials or secrets that may have been disclosed.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Attackers conducted an automated campaign against internet-exposed Vite development servers, primarily exploiting CVE-2026-39364 to seek .env files, AWS and Azure credentials, Terraform and Serverless artifacts, and process-environment data. F5 honeypots recorded 807 session-grouped attacks and about 32,000 raw Vite-related events; the scanners used encoded paths, spoofed crawler user agents, forged forwarding headers, and largely cloud-hosted source infrastructure.
Vite published an advisory for CVE-2026-39364, a high-severity vulnerability that allows unauthenticated retrieval of files blocked by server.fs.deny through crafted query parameters on the /@fs/ route.
CISA added CVE-2025-31125, a related file-access bypass vulnerability whose signatures were later triggered by Vite scanning traffic, to its Known Exploited Vulnerabilities catalog.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.