Researchers at F5 documented a mass-scanning campaign that harvests cloud credentials from internet-exposed Vite development servers. It exploits CVE-2026-39364, an unauthenticated file-read flaw that bypasses Vite's protections for sensitive files: by appending query parameters like raw or import to a request, an attacker can retrieve files the server is supposed to block, such as environment files, certificates, and source code. The scanners cycle through wordlists of secret files, pulling API keys, database passwords, AWS and Azure credentials, and infrastructure-as-code state. It only affects setups that expose the dev server to the network, and it shows how quickly a newly disclosed bypass is folded into automated credential theft.
CERT/CC disclosed two unpatched flaws in Kaltura's HTML5 video player library that let a remote, unauthenticated attacker read files from a server and run code, with only network access to the endpoint required. Both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint, which takes a user-controlled ServiceUrl parameter and passes fetched data to PHP's unserialize without validating it. Supplying a file path lets an attacker read any file the web server can access, including credentials and API keys, while the deserialization also enables code execution. CERT/CC could not reach the vendor, and because the endpoint is exposed on Kaltura's shared multi-tenant infrastructure, the flaws can affect many tenants at once.
Gitea patched a critical flaw in the self-hosted Git platform that lets an unauthenticated attacker read any file the service account can access, needing only a public repository and crafted Org-mode markup. Tracked as CVE-2026-59774 and scored 9.8, it stems from the markup-rendering endpoint: Gitea initializes its Org-mode library without restricting file access, so the include directive accepts absolute paths and returns their contents. No login or write access is required. Gitea warns it can chain to command execution: read the configuration file, extract the internal token, inject a Git hook, and trigger it during an anonymous clone. It affects versions 1.22.1 through 1.27.0, fixed in 1.27.1.
The Ruby on Rails team disclosed a critical flaw in Active Storage that lets an unauthenticated attacker read arbitrary files by uploading a crafted image. Tracked as CVE-2026-66066 and scored 9.5, it affects applications that use the libvips image library and accept image uploads from untrusted users, which is the default in modern Rails. Active Storage passes uploads to libvips without disabling its unsafe image loaders, so a malicious file can read the server process environment, exposing the secret key base, database passwords, cloud storage keys, and API tokens. Those secrets can enable code execution and lateral movement. Rails is not aware of exploitation, and full details are held until August 28.