Skip to content
feed: live
0dayNews
CVE Record
[ CRITICAL ]CVE-2026-61500

Rejetto HFS Weak Signing Key Allows Session Forgery and RCE

Weak session-signing key in Rejetto HFS lets attackers forge admin sessions and execute code remotely. CVSS 4.0 9.3 critical, with active exploitation attempts reported.

cat cve-2026-61500.json
Vendor
Rejetto
Product
HTTP File Server (HFS)
CVSS
9.3
EPSS (exploit probability)
1.0%
Status
exploited-in-wild
Published

CVE-2026-61500 is a weak signing key vulnerability in Rejetto HTTP File Server (HFS). An attacker with network access to the server can recover the session-cookie signing key and forge an administrative session token, enabling account takeover and remote code execution without valid credentials.

Active scanning and exploitation attempts have been confirmed, according to VulnCheck research reported by BleepingComputer and The Hacker News. SecurityWeek notes the flaw was originally discovered using AI-assisted security analysis.

Remediation

Upgrade to Rejetto HFS 3.2.1 or later. See the official 3.2.1 release notes and VulnCheck’s advisory. If immediate upgrade is not possible, take the server offline or restrict network access to trusted hosts only, and audit logs for evidence of session forgery against the admin interface.