Rejetto HFS servers now actively scanned for critical RCE flaw
Refract AI Intelligence Digest
BLUF
Active exploitation of a critical RCE vulnerability in Rejetto HFS is underway.
NEWS
Threat actors are scanning for CVE-2026-61500, a weak signing key flaw in Rejetto HTTP File Server. This vulnerability enables attackers to forge sessions, hijack accounts, and execute arbitrary code remotely on affected systems.
Why I Care
Unpatched servers face immediate risk of full system compromise and data theft due to active scanning campaigns targeting this specific weakness.
Next Steps
Administrators running Rejetto HFS must upgrade to the latest patched version immediately and verify external exposure of their instances.
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [...]
Source: BleepingComputer ·