Lotu Radar About

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

The Hacker News Cybersecurity Score 10/10
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Summary

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and

SecurityThreat Intel

Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.