SecurityWeek·3 min read·hard
Exploitation Hits Rejetto HFS Vulnerability Discovered by AI
I
Ionut Arghire
✦AI Summary
A critical vulnerability in Rejetto HTTP File Server (HFS) is being exploited by threat actors to gain administrative access and remote code execution. The flaw stems from a predictable random number generator used for session cookies, allowing attackers to forge credentials.
Why it matters
This represents a significant security risk for organizations using the software, highlighting the dangers of weak cryptographic implementations.
CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE.
technology
✦
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in