SecurityBreakingUnverified

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and

What happened

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and

Why it matters

The incident may affect operational continuity, asset safety or trust around Security. Watch for verified scope and remediation.

Affected entities

View evidence

1 reports · 1 original report · 1 independent

  1. The Hacker NewsPrimary source · Supports · EN · 100%
    Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE ↗

Claims

  • Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE Observed

Conflicts

No material conflict detected in the available evidence.

Timeline

  1. First reported

Market move following event

Market reaction is not yet available for this asset and time window.

Score explanation

Confidence · formula confidence-2.1.0
Source trust80
Independent corroboration51
Primary evidence35
Claim consistency82
Extraction confidence82
Attribution quality90
Impact · formula impact-2.1.0
Event magnitude100
Market relevance74
Entity significance42
Market breadth45
Novelty68
Urgency100
Ranking · formula rank-1.0.0
Confidence factor0.8425
Freshness factor0.9847
Breaking bonus8
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE | IntelCap