Rejetto HFS session forgery RCE (CVE-2026-61500)
Vulnerability
Updated: 05.10.2026 11:09
· First: 05.10.2026 11:09
· 📰 2 src / 2 articles
· H score: 46
CVE-2026-61500 in Rejetto HTTP File Server (HFS) exposes 3.0.0 through 3.2.0 to session forgery, letting attackers recover a signing key from Math.random() and seize administrator access. A public Python PoC appeared in late September 2026, and VulnCheck later reported active exploitation attempts. The flaw can escalate to remote code execution through the server_code configuration feature. A fix is available in HFS 3.2.1.