Interestana
Home/News/Rejetto HFS Flaw Exploited for Admin Session Forgery, RCE
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Rejetto HFS Flaw Exploited for Admin Session Forgery, RCE

Rejetto HFS Flaw Exploited for Admin Session Forgery, RCE

A critical security vulnerability affecting Rejetto HTTP File Server (HFS) is currently being exploited by attackers, as reported by VulnCheck. The vulnerability, identified as CVE-2026-61500, carries a high CVSS score of 9.3, indicating its severe impact. This flaw is a form of session forgery that arises from the use of a weak pseudo-random number generator (PRNG). The predictability of the PRNG allows an attacker to determine the session key, thereby enabling unauthorized access to administrative functions and potentially leading to remote code execution (RCE).

VulnCheck's analysis reveals that the exploitation involves manipulating the HFS server to generate predictable session tokens. By leveraging this predictability, an attacker can craft a malicious request that impersonates a legitimate administrator. This forged session allows the attacker to gain elevated privileges, effectively taking control of the server. The ability to achieve remote code execution means that attackers can install malware, steal sensitive data, or use the compromised server as a pivot point for further network intrusions. The Rejetto HTTP File Server is a lightweight, standalone file server application designed for easy file sharing, often used in small office or home environments, making its vulnerabilities a concern for a broad range of users.

The exploitation of CVE-2026-61500 highlights a significant risk for users of Rejetto HFS. The vulnerability's nature, tied to a weak PRNG, suggests a fundamental design weakness that could be difficult to patch without a complete overhaul of the session management system. Attackers are actively scanning for and attempting to exploit this flaw, underscoring the urgency for users to secure their HFS installations. The CVSS score of 9.3 places this vulnerability among the most critical, demanding immediate attention from security professionals and system administrators. The implications of successful exploitation range from data theft and system compromise to the potential for the server to be incorporated into botnets.

While specific details regarding the exact methods of exploitation and the extent of current compromise are still emerging, VulnCheck's alert serves as a critical warning. The active exploitation suggests that proof-of-concept exploits are readily available or have been developed by malicious actors. Users of Rejetto HFS are strongly advised to review their security configurations, apply any available patches or workarounds, and consider alternative solutions if the server cannot be adequately secured. The reliance on a weak PRNG is a common pitfall in software development that can have severe security consequences, as demonstrated by this critical flaw in Rejetto HFS.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next