Rejetto HFS servers now actively scanned for critical RCE flaw

Refract AI Intelligence Digest

BLUF

Active exploitation of a critical RCE vulnerability in Rejetto HFS is underway.

NEWS

Threat actors are scanning for CVE-2026-61500, a weak signing key flaw in Rejetto HTTP File Server. This vulnerability enables attackers to forge sessions, hijack accounts, and execute arbitrary code remotely on affected systems.

Why I Care

Unpatched servers face immediate risk of full system compromise and data theft due to active scanning campaigns targeting this specific weakness.

Next Steps

Administrators running Rejetto HFS must upgrade to the latest patched version immediately and verify external exposure of their instances.

Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.