Find notable cyber news and cases, enriched with sources, timelines, and signals.

Rejetto HFS session forgery RCE (CVE-2026-61500)

Vulnerability
First reported
Last updated
Happening score
H score 46
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-61500 in Rejetto HTTP File Server (HFS) exposes 3.0.0 through 3.2.0 to session forgery, letting attackers recover a signing key from Math.random() and seize administrator access. A public Python PoC appeared in late September 2026, and VulnCheck later reported active exploitation attempts. The flaw can escalate to remote code execution through the server_code configuration feature. A fix is available in HFS 3.2.1.

Related Happenings

CISA KEV order for SolarWinds Serv-U CVE-2026-28318

Public Sector Action
H score50 First: 06.06.2026 11:14 Last: 06.06.2026 11:14 Sources 1

About this happening: CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands...

Timeline

  1. 05.10.2026 11:09 1 articles · 3h ago

    Rejetto HFS session forgery RCE (CVE-2026-61500)

    Initial Disclosure

    CVE-2026-61500 was identified in Rejetto HFS 3.0.0 through 3.2.0 as a session-forgery flaw rooted in Math.random()-based key generation. The issue already had a 3.2.1 patch when a public PoC later made exploitation practical.

    Show sources
  2. 05.10.2026 11:09 1 articles · 3h ago

    Unnamed China-based actor targets vulnerable Rejetto HFS hosts with CVE-2026-61500 attempts

    Exploitation Observed

    On October 1, 2026, VulnCheck detected active exploitation attempts against Rejetto HTTP File Server (HFS) CVE-2026-61500. The activity involved an unnamed threat actor in China targeting real vulnerable hosts in the U.S., using a flaw that can let an attacker reconstruct the session-cookie signing key, forge an administrator session, and reach full administrative access and remote code execution.

    Show sources