#3
The Hacker News
general
October 05, 2026 at 08:09 UTC
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
By [email protected] (The Hacker News)
AI Summary
CVE-2026-61500 (CVSS 9.3) in Rejetto HTTP File Server is under active exploitation, allowing attackers to predict session-cookie signing keys via a weak PRNG, enabling admin session forgery and remote code execution. VulnCheck confirmed active exploitation attempts, and the flaw was notably discovered by an AI-assisted vulnerability research process. Administrators running Rejetto HFS should patch immediately as internet-wide scanning for this vulnerability is now underway.
Relevance score: 85.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →