Rejetto HFS session forgery RCE (CVE-2026-61500)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-61500 in Rejetto HTTP File Server (HFS) exposes 3.0.0 through 3.2.0 to session forgery, letting attackers recover a signing key from Math.random() and seize administrator access. A public Python PoC appeared in late September 2026, and VulnCheck later reported active exploitation attempts. The flaw can escalate to remote code execution through the server_code configuration feature. A fix is available in HFS 3.2.1.
Related Happenings
CISA KEV order for SolarWinds Serv-U CVE-2026-28318
Public Sector Action
H score50
First: 06.06.2026 11:14
Last: 06.06.2026 11:14
Sources 1
About this happening:
CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands...
CISA KEV order for SolarWinds Serv-U CVE-2026-28318
Public Sector ActionAbout this happening: CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands...
Timeline
-
05.10.2026 11:09 1 articles · 3h ago
Rejetto HFS session forgery RCE (CVE-2026-61500)
Initial DisclosureCVE-2026-61500 was identified in Rejetto HFS 3.0.0 through 3.2.0 as a session-forgery flaw rooted in Math.random()-based key generation. The issue already had a 3.2.1 patch when a public PoC later made exploitation practical.
Show sources
- Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE — thehackernews.com — 05.10.2026 11:09
-
05.10.2026 11:09 1 articles · 3h ago
Unnamed China-based actor targets vulnerable Rejetto HFS hosts with CVE-2026-61500 attempts
Exploitation ObservedOn October 1, 2026, VulnCheck detected active exploitation attempts against Rejetto HTTP File Server (HFS) CVE-2026-61500. The activity involved an unnamed threat actor in China targeting real vulnerable hosts in the U.S., using a flaw that can let an attacker reconstruct the session-cookie signing key, forge an administrator session, and reach full administrative access and remote code execution.
Show sources
- Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE — thehackernews.com — 05.10.2026 11:09