Active Exploits Target Critical Flaw in Rejetto HTTP File Server, Researchers Warn
VulnCheck security analysts have detected ongoing exploit attempts targeting a freshly disclosed bug in Rejetto HTTP File Server (HFS), the lightweight web‑based file‑sharing tool employed by small enterprises and hobbyist sites around the globe.
Identified as CVE‑2026‑61500, the defect receives a CVSS score of 9.3, marking it as critical. The issue originates from the server’s use of a weak pseudo‑random number generator for session IDs. By predicting or fabricating these IDs, an attacker can seize an administrator’s session and run arbitrary code on the affected machine.
Telemetry from VulnCheck reveals a spike in scanning traffic and exploit payloads targeting HFS installations exposed to the internet. Although the precise count of breached servers is unclear, the observed behavior indicates that threat actors are actively weaponising the flaw instead of just scanning for it.
Rejetto HFS is prized for its straightforwardness, allowing users to share files over HTTP with little setup. Yet that very popularity renders it a tempting low‑effort target for malicious actors. The session‑forgery bug sidesteps authentication, giving attackers administrator‑level rights and opening the door to complete system takeover via remote code execution.
The vendor has confirmed the issue and plans to issue a patched release soon. Until then, security professionals recommend that administrators install any existing updates, implement robust network segmentation, and, if possible, temporarily shut down the web interface. Additionally, watching logs for atypical session behavior and deploying IDS signatures that detect the known exploit patterns can help reduce risk.
The appearance of active exploitation highlights a wider takeaway for the SaaS landscape: even obscure, legacy utilities need regular security updates. As adversaries keep automating scans for vulnerable services, entities using HFS should fast‑track remediation to prevent becoming inadvertent entry points for larger cyber‑attack operations.
Comments (0)
Be the first to comment.
Join the discussion