Home / Oct 06, 2026 / Story
0
#3 The Hacker News general October 05, 2026 at 08:09 UTC

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

By [email protected] (The Hacker News)

AI Summary

CVE-2026-61500 (CVSS 9.3) in Rejetto HTTP File Server is under active exploitation, allowing attackers to predict session-cookie signing keys via a weak PRNG, enabling admin session forgery and remote code execution. VulnCheck confirmed active exploitation attempts, and the flaw was notably discovered by an AI-assisted vulnerability research process. Administrators running Rejetto HFS should patch immediately as internet-wide scanning for this vulnerability is now underway.

Relevance score: 85.0/100

# More from October 06