Cloud Takeover: Mass Scanning for Exposed Vite Endpoints (CVE-2026-39364)
F5, Friday, September 11th, 2026
F5 Labs' September sensor data shows mass scanning for exposed Vite development endpoints.
F5 Labs' September Sensor Intel Series covers mass scanning activity targeting exposed Vite endpoints via CVE-2026-39364.
Vite is a development server, and the recurring problem is that development tooling reaches production or internet-exposed environments where it was never meant to run, exposing filesystem access and configuration. The sensor data quantifies how quickly scanning follows disclosure.
For teams running JavaScript build tooling, the practical check is whether any development server is reachable from outside the build environment.