Rejetto HFS Servers Face Active Scanning for Critical RCE Vulnerability

· Original article ↗

Summary

Rejetto HFS servers are being probed for CVE-2026-61500, a flaw that can enable session forgery, account takeover, and remote code execution. No successful exploitation has been reported; users should upgrade.

Key points

  • VulnCheck honeypots observed small-scale probes targeting CVE-2026-61500 from a single China Telecom IP, probing deployments in Japan and the United States.
  • The flaw affects Rejetto HFS versions 3.0.0 through 3.2.0: predictable Math.random() session-key generation and leaked generator outputs can let unauthenticated attackers forge administrator session cookies.
  • Attackers could use the forged access to execute server-side JavaScript and achieve remote code execution.
  • Horizon3 published technical details and a proof-of-concept exploit on September 30; the article says this may have prompted the scanning.
  • VulnCheck has not reported successful exploitation or post-exploitation activity.
  • The flaw is fixed in HFS 3.2.1; users are advised to upgrade, preferably to the latest stable release, 3.3.4.

Article Details

Vulnerability Types
  • Weak session-cookie signing key generation
  • Leakage of random-number generator outputs to unauthenticated clients
Severity
Critical
Affected Versions
  • Rejetto HFS 3.0.0 through 3.2.0
Exploitation Status
reported
Exploit Availability
public_poc
Patch Status
available

MITRE ATT&CK

CVE

People

Vendors

Products

Countries

Related Articles