Rejetto HFS servers now actively scanned for critical RCE flaw

Rejetto HFS servers now actively scanned for critical RCE flaw
Hackers are scanning for CVE-2026-61500 in Rejetto HFS, a weak session-cookie signing flaw that can lead to administrator session forgery, account takeover, and remote code execution. Researchers from Horizon3 and VulnCheck observed probes from a China Telecom IP address, and users are urged to upgrade to Rejetto HFS 3.2.1 or later. #CVE-2026-61500 #RejettoHFS #Horizon3 #VulnCheck #ChinaTelecom

Keypoints

  • VulnCheck detected active probing for CVE-2026-61500 in Rejetto HFS.
  • The flaw enables session forgery, account takeover, and remote code execution.
  • Observed scanning came from a China Telecom IP address targeting Japan and the United States.
  • Horizon3 used Anthropic’s Mythos model to uncover the weak PRNG and related leak.
  • Users should upgrade to Rejetto HFS 3.2.1 or the latest stable release, 3.3.4.

Read More: https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/