Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.

The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Show HN: Drop – a rootless Linux sandbox with gVisor support

Show HN: Drop – a rootless Linux sandbox with gVisor support Source: Hacker News

The New AI Superpowers: Focus and Followthrough

The New AI Superpowers: Focus and Followthrough Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 20.06.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 167.172.177.125 — 93 requests (recent log) 89.167.35.212 — 68 requests (recent log) 216.73.217.33 — 37 requests (recent