
Why it matters
Operators of Rejetto HFS may face unauthorized access and remote code execution risk if the reported flaw is exploitable in their environment.
What we know
Confirmed by several sources
- Reports say attackers are actively targeting or scanning Rejetto HFS for a flaw involving key predictability and session forgery. — BleepingComputer, The Hacker News
- The vulnerability is identified as CVE-2026-61500. — BleepingComputer, The Hacker News
- The flaw can lead to account takeover and remote code execution. — BleepingComputer, The Hacker News
Reported by one source
- VulnCheck is cited as the source reporting active exploitation attempts. — The Hacker News
- The flaw has a CVSS score of 9.3. — The Hacker News
Coverage 2 publishers
-
Rejetto HFS servers now actively scanned for critical RCE flaw
-
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Articles stay on their publishers’ sites; each link opens the original.