MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 13 h ago, last 13 h ago, peak #1

Attackers Exploit Critical Rejetto HFS Session Forgery Flaw

Original: ⚠️ CRITICAL: Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE Rejetto HFS vulnerability CVE-

A critical vulnerability in Rejetto HTTP File Server, tracked as CVE-2026-61500, lets attackers forge admin sessions and achieve remote code execution through weakly signed session cookies. Security researchers report active exploitation detected in October 2026, with warnings circulating urging administrators to patch exposed HFS servers immediately.

Why now: Active exploitation of a critical flaw granting admin access and code execution makes it urgent for server administrators.

Rejetto HFSCVE-2026-61500

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1222228