bleeping-computer · Crawled Oct 5, 2026

Rejetto HFS servers now actively scanned for critical RCE flaw

1 IoCs 1 CVEs
Read original article ↗

AI Summary

Hackers are actively scanning for a critical remote code execution (RCE) vulnerability, CVE-2026-61500, in Rejetto HFS (HTTP File Server) instances. The flaw stems from a weak session-cookie signing key derived from JavaScript's Math.random() generator, which is also leaked to unauthenticated clients, enabling attackers to reconstruct the key and forge administrator session cookies. Successful exploitation allows full administrative access and remote code execution via server-side JavaScript execution. Probing activity has been observed from a single China Telecom IP address targeting systems in Japan and the United States, likely for reconnaissance ahead of broader exploitation.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 1 extracted

Type Value Detail
IP 117[.]10[.]22[.]133 Details →

MITRE ATT&CK TTPs 7 techniques