Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Summary

A critical security vulnerability, CVE-2026-61500, in Rejetto HTTP File Server (HFS) is being actively exploited. The flaw allows attackers to forge admin sessions and achieve remote code execution by exploiting a weak pseudo-random number generator.

IFF Assessment

FOE

This vulnerability allows attackers to gain unauthorized access and execute code remotely, posing a significant threat to defenders.

Severity

9.8 Critical

Defender Context

Defenders should prioritize patching Rejetto HFS instances immediately, as this vulnerability is actively being exploited. The ease of exploiting a weak PRNG highlights the importance of secure development practices and regular security audits for network-facing services.

Read Full Story →