Detalle de la noticia

Vulnerabilidad

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Fuente: The Hacker News Publicado: 05/10/2026 · 08:09 UTC

También cubierto por: SecurityWeek

Compartir:
Vulnerabilidad Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Imagen: The Hacker News

A cri­ti­cal se­cu­rity flaw im­pac­ting Re­jet­to HTTP File Ser­ver (HFS) is wit­nes­sing ac­ti­ve ex­ploi­ta­tion at­tem­pts, ac­cor­ding to Vuln­Check. The vul­ne­ra­bi­lity in ques­tion is CVE-2026-61500 (CVSS score: 9.3), a case of ses­sion for­gery stem­ming from the use of a weak pseu­do-ran­dom num­ber ge­ne­ra­tor (PRNG) that can lead to a pre­dic­ta­ble key, which an at­tac­ker can then use to gain unautho­ri­zed ac­cess…