Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
A critical Rejetto HTTP File Server flaw (CVE-2026-61500, CVSS 9.3) is seeing active exploitation attempts, according to VulnCheck. The session-forgery bug stems from a weak pseudo-random number generator producing predictable keys, letting attackers gain unauthorized access and potentially achieve remote code execution.