search
HFS
Trends
- 1Attackers Exploit Critical Rejetto HFS Session Forgery Flaw▼⚠️ CRITICAL: Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE Rejetto HFS vulnerability CVE-
A critical vulnerability in Rejetto HTTP File Server, tracked as CVE-2026-61500, lets attackers forge admin sessions and achieve remote code execution through weakly signed session cookies. Security researchers report active exploitation detected in October 2026, with warnings circulating urging administrators to patch exposed HFS servers immediately.
- 2Critical Rejetto HFS Flaw Actively Exploited for Remote Code Execution▼Vulnerability in Rejetto HFS Leads to Remote Code Execution, Actively Exploited A critical authentication bypass is repo
A critical authentication bypass in Rejetto HFS, tracked as CVE-2026-61500, allows attackers to forge administrator sessions and achieve remote code execution. Security researchers report the flaw is being actively exploited in the wild, letting intruders take full control of affected file servers. Administrators are urged to patch exposed HFS instances immediately.
- 3Critical flaw in Rejetto HFS file server under active exploitation●🤖 CVE-2026-61500 (CVSS 9.3): Rejetto HFS 3.0.0–3.2.0 derives its session-cookie signing key from Math.random() and leaks
A critical vulnerability, CVE-2026-61500 with a CVSS score of 9.3, has been disclosed in Rejetto HFS versions 3.0.0 through 3.2.0. The file server derives its session-cookie signing key from the weak Math.random() function and leaks generator output to unauthenticated clients at login, allowing attackers to recover the key, forge an admin cookie and achieve remote code execution. A proof-of-concept has been published and servers are already being scanned. A fixed version is available, and security researchers urge immediate updates.