Hackers actively scanning for CVE-2026-61500 flaw in Rejetto HFS servers
Security researchers report that malicious actors are probing Rejetto HFS servers for a critical vulnerability, CVE-2026-61500, which affects versions 3.0.0 to 3.2.0. The flaw involves weak session cookie signing due to non-cryptographic random number generation, enabling attackers to forge administrator sessions and execute remote code. Observations indicate the scans originate from a China Telecom IP address targeting servers in Japan and the US.
GoKawiil's interpretation of the reporting above, not reported fact.
This active scanning suggests threat actors are assessing the vulnerability's exploitability, which could lead to widespread compromise of self-hosted file servers. The flaw's existence in widely used open-source software underscores the importance of timely patching to prevent potential breaches or malicious control of affected systems.
- Active scans indicate ongoing reconnaissance for the vulnerability.
- The flaw allows session forgery and remote code execution.
- Users should update to version 3.2.1 or later to mitigate risks.
Source: bleepingcomputer.com, 2026-10-05
Published there as: “Rejetto HFS servers now actively scanned for critical RCE flaw”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.