{"id":1728,"date":"2026-09-17T12:10:50","date_gmt":"2026-09-17T06:40:50","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1728"},"modified":"2026-09-21T12:45:29","modified_gmt":"2026-09-21T07:15:29","slug":"vite-cve-2026-39364","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/","title":{"rendered":"Vite CVE-2026-39364 Exploitation: Exposed Dev Servers Targeted for AWS and Azure Secrets"},"content":{"rendered":"<p>Internet-exposed Vite development servers are facing mass scanning designed to uncover cloud credentials and infrastructure secrets. <a href=\"https:\/\/www.f5.com\/labs\/articles\/cloud-takeover-mass-scanning-for-exposed-vite-endpoints-cve-2026-39364?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=vite_cve_2026_39364\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">F5 Labs recorded 807 session-grouped attacks and roughly 32,000 raw events<\/a> during August 2026. The activity included probes matching Vite CVE-2026-39364, alongside attempts targeting older Vite file-access flaws. Attackers systematically requested <code>.env<\/code> files, AWS credentials, Azure data, Terraform state files and process environment data.<\/p>\n<p>Vite CVE-2026-39364 is a high-severity file-read vulnerability that can bypass <code>server.fs.deny<\/code> through crafted query parameters. Vite 7.1.0 through 7.3.1 and 8.0.0 through 8.0.4 are affected. Versions 7.3.2 and 8.0.5 contain the fix. The Vite advisory assigns the vulnerability a CVSS v4.0 score of 8.2.<\/p>\n<p>Importantly, F5&#8217;s telemetry confirms scanning and attempts to retrieve sensitive files. The available reporting does not establish that every request succeeded or that specific AWS or Azure accounts were subsequently compromised.<\/p>\n<h2>Vite CVE-2026-39364 at a Glance<\/h2>\n<table style=\"font-weight: 400; width: 99.335%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"12\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 23.0958%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Detail<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 91.0319%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Information<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 23.0958%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CVE<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 91.0319%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVE-2026-39364<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 23.0958%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Product<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 91.0319%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Vite development server<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 23.0958%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Vulnerability<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 91.0319%;\" data-celllook=\"0\"><span data-contrast=\"auto\"><code>server.fs.deny<\/code> file-access bypass<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 23.0958%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Severity<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 91.0319%;\" data-celllook=\"0\"><span data-contrast=\"auto\">High<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 23.0958%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CVSS<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 91.0319%;\" data-celllook=\"0\"><span data-contrast=\"auto\">8.2, CVSS v4.0<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td style=\"width: 23.0958%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Authentication<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 91.0319%;\" data-celllook=\"0\"><span data-contrast=\"auto\">None\u00a0required<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td style=\"width: 23.0958%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Affected Vite versions<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 91.0319%;\" data-celllook=\"0\"><span data-contrast=\"auto\">7.1.0\u20137.3.1 and 8.0.0\u20138.0.4<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td style=\"width: 23.0958%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Fixed versions<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 91.0319%;\" data-celllook=\"0\"><span data-contrast=\"auto\">7.3.2 and 8.0.5<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td style=\"width: 23.0958%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Exposure condition<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 91.0319%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Vite development server exposed to the network, with\u00a0additional\u00a0filesystem conditions<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td style=\"width: 23.0958%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Observed activity<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 91.0319%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Mass scanning and credential\/configuration-file probing<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td style=\"width: 23.0958%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CISA KEV<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 91.0319%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Not listed as of this review<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>How Vite CVE-2026-39364 Bypasses server.fs.deny<\/h2>\n<p>CVE-2026-39364 allows unauthenticated attackers to bypass Vite&#8217;s <code>server.fs.deny<\/code> restrictions with crafted query parameters. Exploitation requires a network-accessible development server and specific filesystem conditions.<\/p>\n<p>Vite uses <code>server.fs.deny<\/code> to prevent its development server from serving sensitive files. Its default deny list covers files such as <code>.env<\/code>, certificates, private keys and package-manager configuration files.<\/p>\n<p>However, CVE-2026-39364 can bypass this restriction under specific conditions. By appending query parameters such as <code>?raw<\/code>, <code>?import&amp;raw<\/code>, or <code>?import&amp;url&amp;inline<\/code>, an unauthenticated attacker can retrieve files protected by <code>server.fs.deny<\/code> with an HTTP 200 response.<\/p>\n<p>An affected application must meet three conditions:<\/p>\n<ul>\n<li><strong>Network exposure:<\/strong> The Vite development server is exposed through <code>--host<\/code> or <code>server.host<\/code>.<\/li>\n<li><strong>Permitted filesystem location:<\/strong> The requested file exists within directories permitted by <code>server.fs.allow<\/code>.<\/li>\n<li><strong>Denied file pattern:<\/strong> The file matches a pattern configured under <code>server.fs.deny<\/code>.<\/li>\n<\/ul>\n<p>Vite uses <code>localhost<\/code> as the default value for <code>server.host<\/code>. Setting it to <code>0.0.0.0<\/code> or <code>true<\/code> can make the server listen on additional interfaces. Therefore, network exposure is an important prerequisite rather than an inherent property of every Vite installation.<\/p>\n<h2>Why the Scanners Are Looking for Cloud and IaC Secrets<\/h2>\n<p>F5&#8217;s telemetry shows that the campaign goes well beyond checking whether a Vite server responds.<\/p>\n<p>The scanning infrastructure cycled through lists of potentially valuable files. Targets included <code>.env<\/code> variants and AWS credential files across several common user directories. Attackers also probed for Azure data, Terraform state, serverless configuration and process environment information.<\/p>\n<p>Examples included:<\/p>\n<ul>\n<li><code>.env<\/code>, <code>.env.local<\/code> and <code>.env.production<\/code><\/li>\n<li>AWS credential and configuration files<\/li>\n<li>Azure credential and access-token data<\/li>\n<li>Terraform state files<\/li>\n<li>serverless configuration<\/li>\n<li><code>\/proc\/self\/environ<\/code><\/li>\n<li><code>\/etc\/passwd<\/code><\/li>\n<\/ul>\n<p>F5 also observed double-encoded traversal sequences. The researchers assessed that attackers used these techniques to bypass request normalization by intermediate reverse proxies or web application firewalls.<\/p>\n<p>This targeting matters because development environments can contain secrets used by build, deployment and cloud workflows. Exposure of a credential does not automatically mean a cloud account was compromised. However, a valid exposed credential could provide another access path depending on its permissions and validity.<\/p>\n<h2>What F5 Actually Observed in the Vite Scanning Campaign<\/h2>\n<p>F5&#8217;s August telemetry shows that the scanning extended across internet-exposed developer tooling and included probes matching CVE-2026-39364.<\/p>\n<p>Additionally, the activity generated signatures associated with older Vite access-control vulnerabilities, including CVE-2025-30208, CVE-2025-31125 and CVE-2024-45811.<\/p>\n<p>That distinction is important for incident response.<\/p>\n<p>The evidence supports saying that exposed Vite systems were actively scanned and probed for sensitive files. It does not establish that every target returned those files. Nor does the available F5 report document subsequent privilege escalation, lateral movement or persistence inside specific AWS or Azure environments.<\/p>\n<h2>How to Mitigate Vite CVE-2026-39364 on Exposed Dev Servers<\/h2>\n<p>Organizations should address both the vulnerable Vite deployment and any secrets that could have been accessible while the server was exposed.<\/p>\n<ol>\n<li><strong>Upgrade Vite:<\/strong> Update affected deployments to Vite 7.3.2 or 8.0.5 or later. Teams should perform the upgrade through their existing npm, dependency-management or software-deployment workflow.<\/li>\n<li><strong>Restrict network exposure:<\/strong> Remove unnecessary <code>--host<\/code> or <code>server.host<\/code> configurations that expose Vite beyond the intended network boundary. Where remote access is unnecessary, keep the development server bound to <code>localhost<\/code>.<\/li>\n<li><strong>Audit logs:<\/strong> Review Vite, reverse-proxy and relevant network logs for requests containing <code>?raw<\/code>, <code>?import&amp;raw<\/code> or <code>?import&amp;url&amp;inline<\/code>. Investigate systems that received suspicious requests while running an affected Vite version.<\/li>\n<li><strong>Rotate potentially exposed secrets:<\/strong> Rotate AWS or Azure credentials, access tokens and other secrets that may have been accessible through <code>.env<\/code> files, Terraform state or other exposed configuration data.<\/li>\n<\/ol>\n<p>Teams should also review how development servers become externally reachable. Removing unnecessary exposure reduces the attack surface, while log analysis and credential rotation help address potential exposure that occurred before remediation.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Why-XDR-IS-stronger-thumbnail\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Why-XDR-IS-stronger-thumbnail\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why XDR Is Stronger With UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            See how combining UEM with XDR can connect proactive endpoint hygiene with faster threat investigation and containment.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/why-xdr-is-stronger-with-uem\/'>\n                            Download the whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>How Hexnode Supports Endpoint Investigation After Vite Exposure<\/h2>\n<p>The primary remediation for CVE-2026-39364 remains upgrading Vite and restricting unnecessary development-server exposure. Hexnode can complement these measures with endpoint administration, investigation and containment workflows.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align: left;\"><strong>Incident requirement<\/strong><\/th>\n<th style=\"text-align: left;\"><strong>How Hexnode supports it<\/strong><\/th>\n<th style=\"text-align: left;\"><strong>Technical boundary<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align: left;\"><strong>Assess developer endpoints<\/strong><\/td>\n<td style=\"text-align: left;\"><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> provides centralized endpoint management and supports custom scripting. Administrators can use supported scripts for organization-specific checks, such as inspecting configurations or collecting information from managed developer endpoints.<\/td>\n<td style=\"text-align: left;\">Vite is an <code>npm<\/code> package. Teams should upgrade it through the appropriate <code>npm<\/code>, dependency-management or software-deployment workflow. Hexnode UEM should not be positioned as automatically patching the Vite dependency.<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Investigate suspicious endpoint activity<\/strong><\/td>\n<td style=\"text-align: left;\">With <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a>, security teams gain visibility across Windows and macOS endpoints and supports investigation through Precision Threat Hunting.<\/td>\n<td style=\"text-align: left;\">Hexnode XDR should not be positioned as directly detecting CVE-2026-39364 unless specific detection coverage is documented.<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Contain suspicious endpoint activity<\/strong><\/td>\n<td style=\"text-align: left;\">Hexnode XDR provides remediation capabilities such as device isolation, process termination and file quarantine.<\/td>\n<td style=\"text-align: left;\">These endpoint response actions do not replace upgrading Vite or restricting development-server exposure.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The responsibilities remain distinct. Patch and restrict Vite at the development layer, then use endpoint controls to investigate and contain suspicious activity where relevant.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Top-7-Hexnode-XDR-Capabilities-to-Assess-Before-Deployment.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Top 7 Hexnode XDR Capabilities to Assess<\/h4><p>Explore the XDR investigation and remediation capabilities security teams should evaluate when strengthening endpoint threat response.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/hexnode-xdr-deployment-capabilities\/\" aria-label=\"Top 7 Hexnode XDR Capabilities to Assess\"><\/a><\/div><\/div><\/div>\n<h3>Treat Exposed Development Services as Part of the Attack Surface<\/h3>\n<p>When organizations expose development servers, CVE-2026-39364 gives attackers a practical way to discover sensitive secrets through Vite&#8217;s access-control failure.<\/p>\n<p>The campaign&#8217;s targeting is particularly important. The scanners did not simply check Vite versions. They searched for <code>.env<\/code> files, cloud credentials, Terraform state and process environments that could contain operational secrets.<\/p>\n<p>Security and DevOps teams should upgrade to Vite 7.3.2 or 8.0.5 or later, remove unnecessary network exposure and investigate previously exposed instances. Potentially disclosed credentials should also be rotated.<\/p>\n<p>Developer tooling may be temporary. The credentials accessible through it often are not.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Control Across Your Developer Endpoints<\/h5><p>Manage endpoint configurations, deploy supported scripts and strengthen device oversight with Hexnode UEM.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Internet-exposed Vite development servers are facing mass scanning designed to uncover cloud credentials and infrastructure&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1776,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[19,21],"class_list":["post-1728","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud-and-saas","category-patch-management","product_category-unified-endpoint-management","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Vite CVE-2026-39364: Dev Servers Targeted for Secrets<\/title>\n<meta name=\"description\" content=\"Vite CVE-2026-39364 is being probed in mass scans targeting AWS, Azure and Terraform secrets on exposed development servers.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vite CVE-2026-39364: Dev Servers Targeted for Secrets\" \/>\n<meta property=\"og:description\" content=\"Vite CVE-2026-39364 is being probed in mass scans targeting AWS, Azure and Terraform secrets on exposed development servers.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-17T06:40:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-21T07:15:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Vite-CVE-2026-39364-Exploitation-Exposed-Dev-Servers-Targeted-for-AWS-and-Azure-Secrets.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/vite-cve-2026-39364\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/vite-cve-2026-39364\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"Vite CVE-2026-39364 Exploitation: Exposed Dev Servers Targeted for AWS and Azure Secrets\",\"datePublished\":\"2026-09-17T06:40:50+00:00\",\"dateModified\":\"2026-09-21T07:15:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/vite-cve-2026-39364\\\/\"},\"wordCount\":1079,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/vite-cve-2026-39364\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Vite-CVE-2026-39364-Exploitation-Exposed-Dev-Servers-Targeted-for-AWS-and-Azure-Secrets.jpeg?format=webp\",\"articleSection\":[\"Cloud and SaaS\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/vite-cve-2026-39364\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/vite-cve-2026-39364\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/vite-cve-2026-39364\\\/\",\"name\":\"Vite CVE-2026-39364: Dev Servers Targeted for Secrets\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/vite-cve-2026-39364\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/vite-cve-2026-39364\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Vite-CVE-2026-39364-Exploitation-Exposed-Dev-Servers-Targeted-for-AWS-and-Azure-Secrets.jpeg?format=webp\",\"datePublished\":\"2026-09-17T06:40:50+00:00\",\"dateModified\":\"2026-09-21T07:15:29+00:00\",\"description\":\"Vite CVE-2026-39364 is being probed in mass scans targeting AWS, Azure and Terraform secrets on exposed development servers.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/vite-cve-2026-39364\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/vite-cve-2026-39364\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/vite-cve-2026-39364\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Vite-CVE-2026-39364-Exploitation-Exposed-Dev-Servers-Targeted-for-AWS-and-Azure-Secrets.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Vite-CVE-2026-39364-Exploitation-Exposed-Dev-Servers-Targeted-for-AWS-and-Azure-Secrets.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"Vite CVE-2026-39364 Exploitation Exposed Dev Servers Targeted for AWS and Azure Secrets\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/vite-cve-2026-39364\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Vite CVE-2026-39364 Exploitation: Exposed Dev Servers Targeted for AWS and Azure Secrets\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"description\":\"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Vite CVE-2026-39364: Dev Servers Targeted for Secrets","description":"Vite CVE-2026-39364 is being probed in mass scans targeting AWS, Azure and Terraform secrets on exposed development servers.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/","og_locale":"en_US","og_type":"article","og_title":"Vite CVE-2026-39364: Dev Servers Targeted for Secrets","og_description":"Vite CVE-2026-39364 is being probed in mass scans targeting AWS, Azure and Terraform secrets on exposed development servers.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-17T06:40:50+00:00","article_modified_time":"2026-09-21T07:15:29+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Vite-CVE-2026-39364-Exploitation-Exposed-Dev-Servers-Targeted-for-AWS-and-Azure-Secrets.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"Vite CVE-2026-39364 Exploitation: Exposed Dev Servers Targeted for AWS and Azure Secrets","datePublished":"2026-09-17T06:40:50+00:00","dateModified":"2026-09-21T07:15:29+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/"},"wordCount":1079,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Vite-CVE-2026-39364-Exploitation-Exposed-Dev-Servers-Targeted-for-AWS-and-Azure-Secrets.jpeg?format=webp","articleSection":["Cloud and SaaS","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/","url":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/","name":"Vite CVE-2026-39364: Dev Servers Targeted for Secrets","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Vite-CVE-2026-39364-Exploitation-Exposed-Dev-Servers-Targeted-for-AWS-and-Azure-Secrets.jpeg?format=webp","datePublished":"2026-09-17T06:40:50+00:00","dateModified":"2026-09-21T07:15:29+00:00","description":"Vite CVE-2026-39364 is being probed in mass scans targeting AWS, Azure and Terraform secrets on exposed development servers.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Vite-CVE-2026-39364-Exploitation-Exposed-Dev-Servers-Targeted-for-AWS-and-Azure-Secrets.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Vite-CVE-2026-39364-Exploitation-Exposed-Dev-Servers-Targeted-for-AWS-and-Azure-Secrets.jpeg?format=webp","width":1340,"height":754,"caption":"Vite CVE-2026-39364 Exploitation Exposed Dev Servers Targeted for AWS and Azure Secrets"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/vite-cve-2026-39364\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Vite CVE-2026-39364 Exploitation: Exposed Dev Servers Targeted for AWS and Azure Secrets"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"description":"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1728","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1728"}],"version-history":[{"count":6,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1728\/revisions"}],"predecessor-version":[{"id":1804,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1728\/revisions\/1804"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1776"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1728"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1728"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}