MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 1 d ago, last 1 d ago, peak #11

Critical flaw in Rejetto HFS file server under active exploitation

Original: 🤖 CVE-2026-61500 (CVSS 9.3): Rejetto HFS 3.0.0–3.2.0 derives its session-cookie signing key from Math.random() and leaks

A critical vulnerability, CVE-2026-61500 with a CVSS score of 9.3, has been disclosed in Rejetto HFS versions 3.0.0 through 3.2.0. The file server derives its session-cookie signing key from the weak Math.random() function and leaks generator output to unauthenticated clients at login, allowing attackers to recover the key, forge an admin cookie and achieve remote code execution. A proof-of-concept has been published and servers are already being scanned. A fixed version is available, and security researchers urge immediate updates.

Why now: A publicly released proof-of-concept and active scanning make unpatched HFS servers an urgent target for admins right now.

Rejetto HFSCVE-2026-61500

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1229252