Hackers target Rejetto HFS servers following critical session forgery vulnerability discovery
Attackers are actively probing and attempting to exploit a critical remote code execution vulnerability in Rejetto HTTP File Server deployments following public proof of concept code.
FTMQ Security, written by our newsroom0 views

Hackers are actively scanning for and attempting to exploit a critical security vulnerability in Rejetto HTTP File Server, BleepingComputer, The Hacker News, and SecurityWeek reported. The flaw, tracked as CVE-2026-61500, carries a CVSS score of 9.3 and allows attackers to achieve session forgery, account takeover, and remote code execution. VulnCheck observed the active threat activity targeting vulnerable servers. [1][2][3]
According to SecurityWeek, the issue stems from a weak pseudo-random number generator that leaks sensitive information. The Hacker News and SecurityWeek both reported that an attacker can collect a small set of login responses to reconstruct the generator state, recover the session-cookie signing key, and gain administrative access. [2][3]
BleepingComputer reported that VulnCheck Vice President of Security Research Caitlin Condon observed probes from honeypots over the weekend. The activity appeared to be small-scale reconnaissance originating from a single China Telecom IP address that targeted deployments in Japan and the United States. The scans followed the release of a public proof of concept demonstrating administrative session forgery, according to The Hacker News. [1][2]
SecurityWeek reported that VulnCheck initially discovered the weakness in June. Rejetto released HFS version 3.2.1 on July 13 with a patch to resolve the issue. System administrators running affected versions must update to the patched software to prevent unauthorized remote access. [3]
In short
- CVE-2026-61500 is a critical session forgery flaw in Rejetto HFS with a CVSS score of 9.3.
- The vulnerability allows attackers to recover signing keys and gain remote code execution.
- VulnCheck detected reconnaissance probes from a China Telecom IP address.
- Rejetto released a patch for the flaw in HFS version 3.2.1 on July 13.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]Rejetto HFS servers now actively scanned for critical RCE flawBleepingComputer, 18h ago (the report this story comes from)
- [2]Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCEThe Hacker News, 1d ago
- [3]Exploitation Hits Rejetto HFS Vulnerability Discovered by AISecurityWeek, 1d ago
Background
- [4]Comparison of web server software on Wikipedia
Our newsroom writes these reports with the help of software, from the 4 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- Cisco Warns of Active Exploitation in Critical SD-WAN Manager FlawIncident Response, 14h ago
- Microsoft Patches High Severity Privilege Escalation Flaw in Exchange ServerTop Stories, 16h ago
More in Top Stories
- ShinyHunters exploits PeopleSoft zero day hole as FBI arrests suspected member13h ago
- OpenAI introduces invisible text watermarking for ChatGPT and Codex in EU14h ago
- Microsoft Patches High Severity Privilege Escalation Flaw in Exchange Server16h ago
- ClingSTUN Malware Compromises Unpatched IoT Devices as Proxy Nodes16h ago
- China Aligned TA419 Targets US AI Experts With Phishing Attacks1d ago
- Citrix issues emergency updates for NetScaler zero day vulnerability1d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.