Mmastodon TechnologyCybersecurity first seen 13 h ago, last 13 h ago, peak #11
Critical flaw in Rejetto HFS file server under active exploitation
Original: 🤖 CVE-2026-61500 (CVSS 9.3): Rejetto HFS 3.0.0–3.2.0 derives its session-cookie signing key from Math.random() and leaks
A critical vulnerability, CVE-2026-61500 with a CVSS score of 9.3, has been disclosed in Rejetto HFS versions 3.0.0 through 3.2.0. The file server derives its session-cookie signing key from the weak Math.random() function and leaks generator output to unauthenticated clients at login, allowing attackers to recover the key, forge an admin cookie and achieve remote code execution. A proof-of-concept has been published and servers are already being scanned. A fixed version is available, and security researchers urge immediate updates.
Why now: A publicly released proof-of-concept and active scanning make unpatched HFS servers an urgent target for admins right now.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1229252