Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
AI Summary
A critical vulnerability, CVE-2026-61500, in Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0 is under active exploitation, enabling attackers to forge administrator session cookies and achieve remote code execution. The flaw stems from the use of a predictable pseudo-random number generator (Math.random()) for session-cookie signing keys, which can be reconstructed by unauthenticated attackers through login responses. A proof-of-concept exploit was publicly released by researcher Alejandro Ramos (aramosf), and exploitation attempts have been observed, including by an unnamed threat actor based in China targeting U.S. systems. The vulnerability follows previous exploitation of another Rejetto HFS flaw, CVE-2024-23692, which was used to deploy cryptocurrency miners and malware such as HATVIBE.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| GitHub User | aramosf | Details → |