Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Security

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

The Hacker News · Oct 05, 2026

Back to News
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Security October 5, 2026

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.