Mmastodon TechnologyCybersecurity first seen 13 h ago, last 13 h ago, peak #1
Attackers Exploit Critical Rejetto HFS Session Forgery Flaw
Original: ⚠️ CRITICAL: Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE Rejetto HFS vulnerability CVE-
A critical vulnerability in Rejetto HTTP File Server, tracked as CVE-2026-61500, lets attackers forge admin sessions and achieve remote code execution through weakly signed session cookies. Security researchers report active exploitation detected in October 2026, with warnings circulating urging administrators to patch exposed HFS servers immediately.
Why now: Active exploitation of a critical flaw granting admin access and code execution makes it urgent for server administrators.
Evidence
- ⚠️ CRITICAL: Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE Rejetto HFS vulnerability CVE-2026-61500 allows attackers to forge admin sessions and execute code via weak session cookie signing. Active exploitation detected in October 2026 targeting… · threatnoir@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/1222228