HackerFeeds

CyberSecurity News

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

The Hacker News
· October 5, 2026

AI summary

A critical security flaw in Rejetto HTTP File Server is being actively exploited, according to VulnCheck. The vulnerability, identified as CVE-2026-61500 with a CVSS score of 9.3, involves session forgery due to a weak pseudo-random number generator. This weakness can lead to a predictable key, which attackers can use to gain unauthorized access. The flaw can ultimately result in remote code execution. The vulnerability is considered high-severity due to its potential impact. Attackers are targeting this flaw to exploit its potential for admin session forgery and remote code execution.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.