Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Overview
A serious security vulnerability in Rejetto's HTTP File Server (HFS), tracked as CVE-2026-61500, is currently being exploited by attackers. This flaw, which has a CVSS score of 9.3, arises from a weak pseudo-random number generator that allows for session forgery. Essentially, this means that an attacker can predict the session key, granting them unauthorized access to the server. The vulnerability poses a significant risk to users of HFS, as it can lead to remote code execution, allowing attackers to execute commands on the server. Organizations using this software need to take immediate action to protect their systems from potential exploitation.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Rejetto HTTP File Server (HFS)
- Action Required: Users should update to the latest version of Rejetto HFS as soon as possible.
- Timeline: Newly disclosed
Original Article Summary
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and
Impact
Rejetto HTTP File Server (HFS)
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should update to the latest version of Rejetto HFS as soon as possible. Additionally, consider implementing stronger security measures, such as using a more secure random number generator or limiting access to the server to trusted IP addresses.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, RCE, and 1 more.