Rejetto HFS RCE Under Active Exploitation
CVE-2026-61500 is a critical CVSS 4.0 9.3 flaw in Rejetto HFS: attackers can recover the session-signing key, forge admin sessions, and execute code remotely.

A critical flaw in Rejetto’s HTTP File Server is seeing active scanning and exploitation attempts, according to VulnCheck. CVE-2026-61500 carries a CVSS 4.0 score of 9.3 and allows an attacker to recover the session-cookie signing key, forge an administrative session, and from there execute arbitrary code on the server.
BleepingComputer reports that internet-facing HFS instances are under active scan. SecurityWeek notes the flaw was originally discovered using AI-assisted analysis. The Hacker News confirmed the exploitation attempts align with the VulnCheck findings.
What to do
Upgrade Rejetto HFS to the latest patched release. If an upgrade is not immediately possible, take the server offline or restrict network access to trusted sources only, and review your logs for signs of session forgery against the admin interface. Active scanning means the window for patching before exposure is already narrowing.
The flaw
CVE-2026-61500 is a weak signing key in the session-cookie mechanism of Rejetto HFS. An attacker who can communicate with the server can recover the key, then issue a forged session token with administrative privileges. From there, remote code execution follows. The vulnerability class is well understood; the 9.3 CVSS 4.0 score reflects how little friction stands between network access and full server compromise.
Rejetto HFS is a lightweight HTTP file sharing utility that sees real use as an internal file drop and network-adjacent file server in smaller organizations and development environments. It is not, for most operators, a high-visibility asset, and that tends to keep it unpatched longer than it should be.
The AI-discovery angle in SecurityWeek’s write-up is a footnote, not the story. The story is the same one it always is: a small utility with network exposure, a critical flaw, and a patch window that just got shorter.
For the technical advisory and affected versions, see VulnCheck’s CVE-2026-61500 advisory and Rejetto’s HFS 3.2.1 release notes.
See also: YesWiki Auth Bypass Lets Attackers Spoof Identity, Hijack SMTP and DTU Breach Exposes Data of Up to 200,000 Users.
- [ CRITICAL ]CVE-2026-61500Rejetto HFS Weak Signing Key Allows Session Forgery and RCE
Found this useful? Share it.


