CVE-2026-39364Active Exploitation(vitejs / vite)

CRITICALCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 12 mentions and remains active

Immediate actions

  • Patch vitejs vite systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.

8.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-180CWE-284CWE-472

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vite
  • vite\+

Threat summary

  • Active exploitation appears in 21 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 39 mentions across 14 observed days

What's happening

  • Active exploitation reported across 21 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 18 signals
  • Technical details provided in 23 signals
  • Disclosure: 7 classified signals
  • Peaked 8d ago at 12 mentions (2026-09-15); latest day: 1
  • 39 total mentions across 14 days

Affected systems

Products
vitevite\+

Deep dive

Activity timeline39 mentions / 14d
036912Mentions · 2026-04-07: 1Mentions · 2026-04-09: 2Mentions · 2026-04-14: 1Mentions · 2026-05-29: 1Mentions · 2026-09-14: 6Mentions · 2026-09-15: 12Mentions · 2026-09-16: 2Mentions · 2026-09-17: 6Mentions · 2026-09-18: 1Mentions · 2026-09-21: 2Mentions · 2026-09-23: 2Mentions · 2026-09-24: 1Mentions · 2026-10-02: 1Mentions · 2026-10-03: 1PoC Mentioned / Linked · 2026-04-09: 1PoC Mentioned / Linked · 2026-05-29: 1Exploit Tool / Code · 2026-09-15: 2Active Exploitation · 2026-09-14: 5Active Exploitation · 2026-09-15: 9Active Exploitation · 2026-09-16: 2Active Exploitation · 2026-09-17: 3Active Exploitation · 2026-09-21: 1Active Exploitation · 2026-09-23: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-09-14: 4Patch / Workaround · 2026-09-15: 4Patch / Workaround · 2026-09-16: 1Patch / Workaround · 2026-09-17: 1Patch / Workaround · 2026-09-18: 1Patch / Workaround · 2026-09-21: 2Patch / Workaround · 2026-09-23: 2Patch / Workaround · 2026-09-24: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-09: 2Technical Details · 2026-09-14: 2Technical Details · 2026-09-15: 9Technical Details · 2026-09-16: 1Technical Details · 2026-09-17: 4Technical Details · 2026-09-18: 1Technical Details · 2026-09-21: 1Technical Details · 2026-09-23: 1Technical Details · 2026-09-24: 104-0704-0904-1405-2909-1409-1509-1609-1709-1809-2109-2309-2410-0210-03
Signal classification4 categories
Active Exploitation
2156.8%
Patch
821.6%
Disclosure
718.9%
PoC
12.7%
Referenced assets21 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-071
Disclosure1
2026-04-092
Disclosure1Patch1
2026-04-141
Patch1
2026-05-291
PoC1
2026-09-146
Active Exploitation5Disclosure1
2026-09-1512
Active Exploitation9Disclosure2Patch1
2026-09-162
Active Exploitation2
2026-09-176
Active Exploitation3Disclosure2Patch1
2026-09-181
Patch1
2026-09-212
Active Exploitation1Patch1
2026-09-232
Active Exploitation1Patch1
2026-09-241
Patch1
Full discourse20 posts
  • White Knight Labs@WKL_cyber
    Active Exploitation

    Attackers are scanning exposed Vite dev servers using CVE-2026-39364 to pull AWS keys, Azure tokens, and .env files in plaintext. Affects Vite 7.1.0-7.3.2 and 8.x before 8.0.5. Over 800 attacks observed by F5. Patch and rotate secrets now. Full @BleepinComputer article: https://bit.ly/4cTHHYJ

    Post summary

    Attackers are actively scanning exposed Vite dev servers for CVE-2026-39364 to steal credentials, with over 800 attacks observed and a recommendation to patch and rotate secrets.

    020172725
    924 followersView on X
  • Es Geeks@EsGeeks
    Active Exploitation

    🚨 VITE abierto a internet = claves AWS/Azure robadas F5 detectó escaneos masivos. Atacantes leen .env y tokens de la nube con CVE-2026-39364. No expongas el puerto 5173. Actualiza y rota secrets YA. #Vite #CloudSecurity #Ciberseguridad https://t.co/khaUWzdwKx

    Post summary

    The tweet reports that CVE-2026-39364 is being actively exploited in the wild, with attackers scanning exposed VITE instances and reading .env files and cloud tokens. It advises closing port 5173 and updating/rotating secrets immediately.

    11082777
    22.5K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Vite patches critical flaws (CVE-2026-39364 & CVE-2026-39363) allowing arbitrary file reads and .env leaks via WebSockets and query params. Upgrade to 8.0.5! #ViteJS #CyberSecurity #InfoSec #WebDev #Vulnerability #HMR #Frontend #JavaScript https://securityonline.info/vite-vulnerabilities-cve-2026-39364-arbitrary-file-read/ https://t.co/qakJVmhUYt

    Post summary

    Vite has patched CVE-2026-39363 and CVE-2026-39364, which allowed arbitrary file reads and .env leaks via WebSockets and query parameters; users are advised to upgrade to version 8.0.5.

    01064472
    12.3K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    The Vite development server vulnerability CVE-2026-39364 is exploited in mass scanning for credential harvesting. F5 Labs logged 32,000 events. Patch now. #Vite #CVE202639364 #CloudSecurity #CredentialHarvesting #DevSecOps #FileDisclosure #InfoSec #AWS https://securityonline.info/vite-cve-2026-39364-exploited/

    Post summary

    The text highlights that CVE-2026-39364 is actively exploited in mass scanning for credential harvesting, supported by evidence from F5 Labs, and urges immediate patching.

    11051432
    13.0K followersView on X
  • tpx Security ⠠⠵@tpx_Security
    Active Exploitation

    F5 Labs detectó un escaneo masivo automatizado que aprovecha la vulnerabilidad CVE-2026-39364 (CVSS 8.2) en servidores de desarrollo de Vite expuestos a la red. Al manipular parámetros de consulta como ?raw o ?import&raw, atacantes no autenticados evaden las restricciones de server.fs.deny para extraer archivos .env, claves secretas de AWS y Azure, estados de Terraform y archivos del sistema en texto plano.

    Post summary

    The post reports F5 Labs detecting mass automated scanning that actively exploits CVE-2026-39364 in exposed Vite dev servers, with specific bypass and data-extraction details.

    10040363
    3.8K followersView on X
  • ProtAAPP - Protege las AAPP@ProtAAPP

    Investigadores de Hispasec alertan: atacantes explotan CVE-2026-39364 en Vite para robar secretos AWS/Azure. Si usas v7.1-7.3.1 o v8-8.0.4, actualiza ya. https://unaaldia.hispasec.com/una-campana-automatizada-saquea-servidores-de-desarrollo-vite-expuestos-para-robar-secretos-de-aws-y-azure/?utm_source=rss&utm_medium=rss&utm_campaign=una-campana-automatizada-saquea-servidores-de-desarrollo-vite-expuestos-para-robar-secretos-de-aws-y-azure https://t.co/ke4hOEf9ol

    01030272
    8.3K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-39364 - high 🚨 Vite Dev Server - Directory Traversal > Vite is a modern frontend build tool. In Vite prior to versions 6.4.3, 6.3.4, and 5.4... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-39364 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a high‑severity directory traversal flaw in Vite prior to version 6.4.3, linking to a Project Discovery library entry, but offers no evidence of active exploitation, patch status, or exploit code.

    01021160
    916 followersView on X
  • Security Boulevard@securityblvd
    Active Exploitation

    Attackers are mass-scanning exposed Vite servers to exploit CVE-2026-39364 and steal AWS credentials, Azure tokens and other sensitive infrastructure data. Read more: https://buff.ly/C3M6JLR #Cybersecurity #Vite #CloudSecurity #VulnerabilityManagement #DevSecOps

    Post summary

    The text directly reports that attackers are actively mass-scanning and exploiting CVE-2026-39364 on exposed Vite servers to steal cloud credentials, with a reference link to further details but no specific exploit code, patch, or technical vulnerability classification included in the text.

    20100335
    7.0K followersView on X
  • Mathieu BROUTIN@mathieubroutin
    Patch

    Votre dev server Vite sert peut-être votre .env en clair. CVE-2026-39364 : sur un dev server Vite, un ?raw sur un chemin interne contourne server.fs.deny Corrigé en 7.3.2 / 8.0.5. https://t.co/fPLWYkSVTS

    Post summary

    The tweet discloses CVE-2026-39364, a Vite dev server path-bypass vulnerability exposing .env files via ?raw, and states it is patched in versions 7.3.2 and 8.0.5.

    0101065
    49 followersView on X
  • sunil kumawat@Sunil_kumawat17
    Disclosure

    `--host` on a Vite dev server isn’t “sharing the preview” — it’s putting `.env` and cloud creds on a mass-scan wordlist (CVE-2026-39364).

    Post summary

    This tweet discloses CVE-2026-39364, explaining that Vite's `--host` flag exposes `.env` and cloud credentials to mass scanners. It provides technical details about the vulnerability but lacks PoC links, named exploit tools, patch information, or explicit claims of active exploitation.

    01010144
    23 followersView on X
  • sunil kumawat@Sunil_kumawat17
    Disclosure

    Internet-exposed Vite dev servers are mass-scanned for AWS keys, Azure tokens & Terraform state: CVE-2026-39364 (CVSS 8.2). F5 saw ~32k probes in August. Disclosed in April. The habit: `--host`/Docker maps 5173 to the world, then `.env` walks out.

    Post summary

    The text discloses CVE‑2026‑39364, noting that Internet‑exposed Vite development servers are being mass‑scanned for cloud credentials, with about 32 k probes observed in August, but does not mention a PoC, exploit tool, or patch.

    1001076
    23 followersView on X
  • Eyal Estrin ☁️@eyalestrin
    Disclosure

    Cloud Takeover: Mass Scanning for Exposed Vite Endpoints (CVE-2026-39364) https://dlvr.it/TVTx04 #appsec

    Post summary

    The tweet discloses a newly identified cloud takeover vulnerability (CVE-2026-39364) affecting exposed Vite endpoints, noting mass scanning activity. No remediation, exploit, or proof-of-concept details are provided.

    0001196
    2.0K followersView on X
  • Threat Landscape@LandscapeThreat
    Active Exploitation

    A mass-scanning operation is exploiting exposed Vite development servers to retrieve cloud credentials, configuration data, and other secrets from AWS and Azure environments. - Attackers exploit CVE-2026-39364 by manipulating query parameters to bypass file-access restrictions and return protected files in plaintext. - Scanning targets environment files, AWS and Azure credentials, Terraform state, serverless configurations, process environment data, and system files, with traversal and encoding variants used to evade filtering. - F5 observed more than 800 attacks and approximately 32,000 events over one month; activity originated mainly from the United States, Belgium, and the Netherlands and used Google Cloud IP ranges. - Related activity also exploited CVE-2025-30208, CVE-2025-31125, and CVE-2024-45811. Exposed servers should be patched and reachable secrets rotated.

    Post summary

    The text reports active mass-scanning exploitation of CVE-2026-39364 in Vite development servers to access sensitive files, with evidence of widespread real-world attacks and a recommendation to patch and rotate secrets.

    0002081
    98 followersView on X
  • Corban Villa@corban_villa
    PoC

    @princechaddha @neo_ai_engineer Added! Congratulations @neo_ai_engineer on the Vite exploit (CVE-2026-39364), looks like a high-quality find :) https://t.co/Du7QebyD9J

    Post summary

    The tweet announces that an exploit (CVE‑2026‑39364) has been discovered and links to a likely proof‑of‑concept, but provides no further details on technical aspects or active exploitation.

    00011183
    123 followersView on X
  • Bhavesh Verma@xbhaveshverma

    Vite Dev Servers Are Being Mass-Scanned to Steal AWS and Azure Cloud Credentials, 16,400+ Instances Exposed. A mass-scanning campaign is exploiting CVE-2026-39364 in Internet exposed Vite development servers to harvest AWS and Azure credentials, (.)env files, and Terraform infrastructure state files. The credential harvesting activity was observed in August and September 2026. Telemetry from Cortex Xpanse indicated over 16,400 exposed instances at the time, affecting sectors including financial services, healthcare, and government across multiple continents. Development servers that are accidentally exposed to the internet have become a primary entry point for cloud credential theft, and the secrets they contain can unlock far more than the dev environment itself.

    0001061
    110 followersView on X
  • Interchouette ITC · ITCy 🦉@Interchouette
    Active Exploitation

    🚨 Hackers are probing exposed Vite servers for AWS/ Azure secrets, and it’s massive. 🚀 CVE-2026-39364 lets them steal env files, credentials, and infra configs without logging in. 🐾 Fix it fast: update to Vite 7.3.2 or 8.0.5+ and restrict access. 🔐

    Post summary

    The text highlights active exploitation attempts targeting exposed Vite servers to steal credentials via CVE-2026-39364, while explicitly recommending patching to Vite 7.3.2 or 8.0.5+ and restricting access.

    1000078
    136 followersView on X
  • Venkata Satish Guttula 🛰️@snakeyesV1
    Patch

    News: Vite CVE-2026-39364 lets scanners with no login read .env and cloud keys from exposed Vite 7.1-7.3.1 and 8.0-8.0.4. F5 saw about 32k August probes for AWS, Azure, and Terraform secrets. Upgrade to 7.3.2 or 8.0.5+, lock port 5173, rotate leaked keys. https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html

    Post summary

    The text discloses an unauthenticated Vite information-disclosure issue affecting specified versions, reports observed probing, and recommends upgrading, restricting port 5173, and rotating exposed credentials.

    00010143
    3.0K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Active Exploitation

    Viteの脆弱性 CVE-2026-39364を狙う大規模スキャン F5が8月に約3.2万件観測、AWS・Azure認証情報を探索 https://rocket-boys.co.jp/security-measures-lab/vite-cve-2026-39364-32000-activity-report/ #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    Post summary

    The text reports large-scale scanning activity targeting CVE-2026-39364 with ~32,000 observations by F5, including cloud credential exploration, indicating active exploitation—but lacks patch, PoC, or technical vulnerability details.

    10000141
    686 followersView on X
  • CloudSecurityAlliance@cloudsa
    Active Exploitation

    CISO Daily Briefing: Cisco Email Gateway 0-day (CVE-2026-76461, CVSS 9.8) hit root RCE pre-patch, KEV-listed, FCEB fix due 9/17. Vite dev server bug (CVE-2026-39364) fueling mass cloud-cred harvesting. Red Heron turned a Gitea RCE into 13 breaches across defense/energy/telecom in days. EU CRA reporting platform now live—24h/72h/14-day clocks binding. DDRop's $200 rig cracks Intel/AMD confidential-computing attestation, threatening cloud AI isolation. https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-september-16-2026

    Post summary

    The briefing reports active exploitation of several CVEs—most notably a Cisco Email Gateway zero‑day on CISA’s KEV list and a Gitea RCE used in multiple breaches—alongside credential‑stealing Vite server bugs and a new hardware attestation bypass tool.

    10000514
    18.9K followersView on X
  • Threat Landscape@LandscapeThreat
    Active Exploitation

    Automated scanning in August 2026 increasingly exploited exposed Vite development servers to steal cloud credentials and deployment data. - Attackers abused CVE-2026-39364, an unauthenticated access-control bypass affecting specified Vite versions, by manipulating query parameters on the internal @ fs route. - Scanners also tested CVE-2025-30208, CVE-2025-31125, and CVE-2024-45811 using extensive wordlists targeting environment files, AWS and Azure credential stores, Terraform state, serverless artifacts, and Linux process data. - Honeypot telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events; exposed files could enable cloud account takeover, lateral movement, or broader infrastructure compromise. VULNERABILITY CVE-2024-45811 CVE-2025-30208 CVE-2025-31125 CVE-2026-39364

    Post summary

    The text reports active real-world exploitation of Vite development servers through CVE-2026-39364 and related scanning activity, supported by honeypot telemetry and technical abuse details. No patch or named exploit tool is mentioned.

    0001044
    74 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appvitejsvite-node.js-
Appvoidzerovite\+-node.js-

Explore more