Back to all news
Security

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

The Hacker News·October 5, 2026·1 min read
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Attackers are actively exploiting a critical vulnerability in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500 with a CVSS score of 9.3. The flaw involves session forgery due to a weak pseudo-random number generator, allowing attackers to gain unauthorized access and potentially achieve remote code execution. VulnCheck reported the active exploitation attempts, urging users to update immediately.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store