importantSYS.SOURCE: The Hacker News• 2026-10-05T13:39:23+05:30
Critical Session Forgery Vulnerability in Rejetto HFS Enables Remote Code Execution
A critical vulnerability (CVE-2026-61500) in Rejetto HTTP File Server allows attackers to forge admin sessions and achieve remote code execution through a weak pseudo-random number generator. Active exploitation attempts have been observed, with threat actors in China targeting vulnerable systems in the U.S.
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.
The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and
*** END OF TRANSMISSION ***