Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Summary
A critical security vulnerability, CVE-2026-61500, in Rejetto HTTP File Server (HFS) is being actively exploited. The flaw allows attackers to forge admin sessions and achieve remote code execution by exploiting a weak pseudo-random number generator.
IFF Assessment
FOE
This vulnerability allows attackers to gain unauthorized access and execute code remotely, posing a significant threat to defenders.
Severity
9.8
Critical
Defender Context
Defenders should prioritize patching Rejetto HFS instances immediately, as this vulnerability is actively being exploited. The ease of exploiting a weak PRNG highlights the importance of secure development practices and regular security audits for network-facing services.