Rejetto HFS servers now actively scanned for critical RCE flaw
Summary
Hackers are actively scanning for a critical vulnerability (CVE-2026-61500) in Rejetto HTTP File Server (HFS) that allows for session forgery, account takeover, and remote code execution (RCE). This flaw stems from a weak signing key implementation within the server software.
IFF Assessment
FOE
The vulnerability allows for remote code execution, which is a severe threat that attackers can exploit to compromise systems.
Severity
9.8
Critical
Defender Context
This actively scanned vulnerability presents an immediate threat to organizations using Rejetto HFS. Defenders should prioritize patching or mitigating this RCE flaw to prevent unauthorized access and potential system compromise. The active scanning indicates that exploit code is likely available and in widespread use.