Rejetto HFS Servers Face Active Scanning for Critical RCE Vulnerability

Summary
Rejetto HFS servers are being probed for CVE-2026-61500, a flaw that can enable session forgery, account takeover, and remote code execution. No successful exploitation has been reported; users should upgrade.
Key points
- VulnCheck honeypots observed small-scale probes targeting CVE-2026-61500 from a single China Telecom IP, probing deployments in Japan and the United States.
- The flaw affects Rejetto HFS versions 3.0.0 through 3.2.0: predictable Math.random() session-key generation and leaked generator outputs can let unauthenticated attackers forge administrator session cookies.
- Attackers could use the forged access to execute server-side JavaScript and achieve remote code execution.
- Horizon3 published technical details and a proof-of-concept exploit on September 30; the article says this may have prompted the scanning.
- VulnCheck has not reported successful exploitation or post-exploitation activity.
- The flaw is fixed in HFS 3.2.1; users are advised to upgrade, preferably to the latest stable release, 3.3.4.
Article Details
- Vulnerability Types
- Weak session-cookie signing key generation
- Leakage of random-number generator outputs to unauthenticated clients
- Severity
- Critical
- Affected Versions
- Rejetto HFS 3.0.0 through 3.2.0
- Exploitation Status
- reported
- Exploit Availability
- public_poc
- Patch Status
- available
MITRE ATT&CK
CVE
People
Vendors
Products
Countries
JapanCondon said the observed activity appears to be small-scale reconnaissance from a single China Telecom IP address probing deployments in Japan and the United States.United StatesCondon said the observed activity appears to be small-scale reconnaissance from a single China Telecom IP address probing deployments in Japan and the United States.