Rejetto HFS Weak Signing Key Allows Session Forgery and RCE
Weak session-signing key in Rejetto HFS lets attackers forge admin sessions and execute code remotely. CVSS 4.0 9.3 critical, with active exploitation attempts reported.
- Vendor
- Rejetto
- Product
- HTTP File Server (HFS)
- CVSS
- 9.3
- EPSS (exploit probability)
- 1.0%
- Status
- exploited-in-wild
- Published
CVE-2026-61500 is a weak signing key vulnerability in Rejetto HTTP File Server (HFS). An attacker with network access to the server can recover the session-cookie signing key and forge an administrative session token, enabling account takeover and remote code execution without valid credentials.
Active scanning and exploitation attempts have been confirmed, according to VulnCheck research reported by BleepingComputer and The Hacker News. SecurityWeek notes the flaw was originally discovered using AI-assisted security analysis.
Remediation
Upgrade to Rejetto HFS 3.2.1 or later. See the official 3.2.1 release notes and VulnCheck’s advisory. If immediate upgrade is not possible, take the server offline or restrict network access to trusted hosts only, and audit logs for evidence of session forgery against the admin interface.
