Cybersecurity · October 6, 2026
Security researchers at VulnCheck report active attacks against Rejetto's HTTP File Server, targeting a critical flaw tracked as CVE-2026-61500 with a CVSS score of 9.3. The bug comes from a weak random-number generator that produces predictable session keys, letting attackers forge an administrator session and ultimately execute code on the server. BleepingComputer separately confirmed mass scanning for vulnerable HFS instances is already underway.
// source: thehackernews.com ↗