Hispasec•September 29, 2026•🇪🇸Translated from Spanish

Automated Scans Exploit CVE-2026-39364 in Exposed Vite Dev Servers to Steal AWS and Azure Secrets

A wave of mass scans is targeting internet-exposed Vite development servers to extract sensitive files and obtain credentials for AWS and Microsoft Azure. The attacks exploit CVE-2026-39364, a flaw that allows unauthenticated file reads by bypassing the dev server’s access controls.

Security researchers have observed a sustained automated campaign that systematically probes publicly reachable Vite instances for clear-text secrets, with particular focus on AWS keys and Azure tokens. The activity relies on CVE-2026-39364 and has continued for weeks, producing thousands of repetitive, industrialized requests.

The vulnerability enables attackers to read files without authentication by circumventing the server.fs.deny mechanism. Malicious requests combine parameters such as ?raw and ?import to force the server to return the contents of targeted files. The distinctive symptom is an HTTP 200 response to requests against the /@fs/ endpoint.

Affected versions include Vite 7.1.0 up to but not including 7.3.2, and Vite 8.x up to but not including 8.0.5. Attackers are not primarily interested in application source code; they seek any file visible to the host, including .env files and infrastructure-as-code artifacts such as terraform.tfstate.

The campaign enumerates long lists of paths and filenames while employing path traversal and double-encoding techniques to evade reverse proxies and WAFs. A portion of the traffic originates from Google Cloud ranges 34.x and 35.x. Honeypot sensors recorded 807 sessions and approximately 32,000 events over a monthly window.

The risk is highest when development teams expose the server using the --host flag, server.host settings, or Docker port mappings. The default port 5173 becomes an entry point once reachable from the internet.

Immediate actions include upgrading to Vite 7.3.2, 8.0.5 or later, binding the server to localhost only, and blocking external access to port 5173 at the perimeter. Additional mitigations involve denying requests to /@fs/ and creating detection rules for suspicious query patterns. Any organization that previously exposed a vulnerable instance should rotate all potentially accessible secrets without delay.

Related articles

Habr•Vulnerabilities & Exploits

cKEV Index Launches to Prioritize Vulnerabilities Using Urgent Patch Score Methodology

CyberOK has introduced the open cKEV Index, a catalog of high-priority vulnerabilities based on the Urgent Patch Score (UPS) framework that tracks signals such as exploit publication and confirmed attacks. The index addresses the growing gap between accelerated vulnerability discovery powered by AI and the slower pace of patching, testing, and deployment in real environments. It incorporates timelines from sources including Anthropic reports on AI-assisted campaigns GTG-50014 and GTG-50029, the rust-in-peace framework, Microsoft Exchange Server Subscription Edition delays, and Oracle’s record 1,434 CVE fixes. UPS defines progressive phases from Radar to Emergency/IR, allowing teams to link specific events like PoC releases or CISA KEV additions to concrete actions under resource constraints. Research using 2025 CISA KEV data shows that early signals enable 35–53% of patches to be completed before official exploitation confirmation. The public version displays only Urgent Patch and Emergency stages with event histories, while full data and API access are available to CyberOK customers.

Security NEXT•Vulnerabilities & Exploits

Multiple Vulnerabilities Found in WatchGuard Access Points Including Critical Flaw

WatchGuard Technologies has disclosed three vulnerabilities affecting its WatchGuard AP access point products, one of which is rated critical. The issues were detailed in an advisory published on September 28 and involve flaws in internal API services and a diagnostic command-line interface. CVE-2026-86102 allows OS command injection that can lead to arbitrary shell command execution on the underlying operating system when an attacker has network access. CVE-2026-101891 stems from improper access controls that permit unauthenticated acquisition of valid API sessions. CVE-2026-87969 affects the diagnostic CLI and enables arbitrary OS command execution but requires administrator privileges to exploit. The findings were reported by Security NEXT.

BoletimSec•Vulnerabilities & Exploits

CISA Adds Two Critical Citrix NetScaler Flaws to Known Exploited Vulnerabilities Catalog

The CISA has added two critical vulnerabilities affecting Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities catalog following reports of active global exploitation. Both CVE-2026-88771 and CVE-2026-88772 carry a CVSS score of 9.5 and were patched by Citrix on September 27, the same day they were added to the catalog. The first flaw stems from improper input validation and allows unauthenticated arbitrary command execution on default installations. The second issue involves a buffer overflow that can lead to remote code execution or denial of service when DTLS is enabled on VPN virtual servers. Affected versions include 14.1-73.32, 13.1-63.21 and earlier, with fixes available in 14.1-73.37, 13.1-64.23 and later releases including FIPS variants. The issues were identified by watchTowr on September 26, and Citrix confirmed ongoing attacks against unpatched systems. Organizations are advised to apply patches immediately while preserving evidence and following full incident response procedures.

AntiMalware•Vulnerabilities & Exploits

Apple Patches Zero-Day CVE-2026-86950 in CoreGraphics Exploited in Targeted iOS Attacks

Apple has released emergency security updates for iPhone, iPad, and multiple macOS versions to address a zero-day vulnerability tracked as CVE-2026-86950. The flaw resides in the CoreGraphics framework responsible for rendering images, text, and 2D graphics. It was discovered by Meta Product Security and confirmed to have been used in sophisticated, targeted attacks against specific iOS users. The vulnerability is an out-of-bounds write that could allow arbitrary code execution when processing a specially crafted file. Apple states the attacks were highly selective rather than widespread. Patches are included in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. An erroneous CVE identifier, CVE-2026-20700, appeared in some early reports.