The Hacker News

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and

By The Hacker News

1 min read
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Got news to share with the events industry?

Submit a press release or story tip and reach thousands of event professionals.

Get in touch→

More in Cybersecurity, Cryptography & Digital Trust

Related Insights