Rejetto HFS servers now actively scanned for critical RCE flaw

Summary

Hackers are actively scanning for a critical vulnerability (CVE-2026-61500) in Rejetto HTTP File Server (HFS) that allows for session forgery, account takeover, and remote code execution (RCE). This flaw stems from a weak signing key implementation within the server software.

IFF Assessment

FOE

The vulnerability allows for remote code execution, which is a severe threat that attackers can exploit to compromise systems.

Severity

9.8 Critical

Defender Context

This actively scanned vulnerability presents an immediate threat to organizations using Rejetto HFS. Defenders should prioritize patching or mitigating this RCE flaw to prevent unauthorized access and potential system compromise. The active scanning indicates that exploit code is likely available and in widespread use.

Read Full Story →