bleeping-computer · Crawled Oct 5, 2026
Rejetto HFS servers now actively scanned for critical RCE flaw
1 IoCs 1 CVEs
Read original article ↗
AI Summary
Hackers are actively scanning for a critical remote code execution (RCE) vulnerability, CVE-2026-61500, in Rejetto HFS (HTTP File Server) instances. The flaw stems from a weak session-cookie signing key derived from JavaScript's Math.random() generator, which is also leaked to unauthenticated clients, enabling attackers to reconstruct the key and forge administrator session cookies. Successful exploitation allows full administrative access and remote code execution via server-side JavaScript execution. Probing activity has been observed from a single China Telecom IP address targeting systems in Japan and the United States, likely for reconnaissance ahead of broader exploitation.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 117[.]10[.]22[.]133 | Details → |
MITRE ATT&CK TTPs 7 techniques
T1059 Command and Scripting Interpreter · Execution T1059.007 JavaScript · Execution T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1210 Exploitation of Remote Services · Lateral Movement T1552 Unsecured Credentials · Credential Access T1552.005 Cloud Instance Metadata API · Credential Access