CyberSecurity News
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
AI summary
A critical security flaw in Rejetto HTTP File Server is being actively exploited, according to VulnCheck. The vulnerability, identified as CVE-2026-61500 with a CVSS score of 9.3, involves session forgery due to a weak pseudo-random number generator. This weakness can lead to a predictable key, which attackers can use to gain unauthorized access. The flaw can ultimately result in remote code execution. The vulnerability is considered high-severity due to its potential impact. Attackers are targeting this flaw to exploit its potential for admin session forgery and remote code execution.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

