Hackers actively scanning for CVE-2026-61500 flaw in Rejetto HFS servers
Security researchers report that malicious actors are probing Rejetto HFS servers for a critical vulnerability, CVE-2026-61500, which affects versions 3.0.0 to 3.2.0. The flaw involves weak session cookie signing due to non-cryptographic random number generation, enabling attackers to forge administrator sessions and execute remote code. Observations indicate the scans originate from a China Telecom IP address targeting servers in Japan and the US.