Critical Rejetto HFS vulnerability exploited in active attacks
Cybersecurity researchers report a critical security vulnerability (CVE-2026-61500) in Rejetto HTTP File Server is under active exploitation. The flaw allows attackers to predict the session-cookie signing key, enabling them to forge administrator sessions and gain full control over affected systems. Though a patch was issued in July 2026, widespread attacks began after a proof-of-concept exploit was released in late September. Threat actors have since targeted exposed servers, mainly in the United States.
- CVE-2026-61500 allows admin session forgery and code execution
- Flaw stems from weak session key generation
- Patch released in July 2026 as version 3.2.1
- Proof-of-concept exploit made public in September
- Attacks detected against U.S. servers starting October 1
Sources covering this
More in Cybersecurity
ClingSTUN malware exploits IoT vulnerabilities as stealth proxy network
A new Linux malware, called ClingSTUN or Cling, is turning unpatched and vulnerable internet-facing IoT devices into remote-controlled…
CrowdStrike launches Falcon Data Security for SaaS in Microsoft 365
CrowdStrike has announced general availability of Falcon Data Security for SaaS, a new product that secures sensitive data within…
Meta fixed major security flaw in Muse AI before launch
Meta engineers identified and urgently fixed several security vulnerabilities in its Muse AI agent just weeks before launch, according…
Dell System Update flaw exposes servers to remote code execution
Dell has alerted customers to a critical security flaw in its System Update tool for PowerEdge servers, which could allow remote…