Security

Rejetto HFS vulnerability draws active exploitation attempts

Reports describe active scanning or exploitation attempts against Rejetto HTTP File Server, with a weak signing key or predictable key enabling session forgery and potentially remote code execution.

Image: The Hacker News

Why it matters

Operators of Rejetto HFS may face unauthorized access and remote code execution risk if the reported flaw is exploitable in their environment.

What we know

Confirmed by several sources

Reported by one source

Coverage 2 publishers

  1. BleepingComputer

    Rejetto HFS servers now actively scanned for critical RCE flaw

  2. The Hacker News

    Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Articles stay on their publishers’ sites; each link opens the original.