September 16, 2026
- CVE-2026-39364 is being mass-scanned for cloud secrets on exposed Vite development servers. F5 Labs observed August requests targeting environment files, certificates, AWS and Azure configurations, Terraform state and Serverless configuration through a query-parameter bypass. Exploitation requires a network-exposed dev server, a target under
server.fs.allowand a matchingserver.fs.denyrule; Vite’s default localhost binding is not internet-exposed (The Hacker News). · Vulnerabilities & Exploitation
in CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways