TechRadar News.
Technology

Researchers Alert: Active Attacks Exploit Critical Vulnerability in Rejetto HTTP File Server

Researchers Alert: Active Attacks Exploit Critical Vulnerability in Rejetto HTTP File Server

VulnCheck security analysts have detected ongoing attacks exploiting a freshly announced flaw in Rejetto HTTP File Server (HFS), the lightweight web‑based file‑sharing tool employed by small enterprises and hobbyist websites around the globe.

Identified as CVE‑2026‑61500, the vulnerability holds a CVSS score of 9.3, marking it as critical. The issue originates from the server’s use of an inadequate pseudo‑random number generator for session IDs. By forecasting or fabricating these IDs, threat actors can seize an administrator’s session and run arbitrary code on the affected machine.

Telemetry from VulnCheck reveals a rise in scans and exploit payloads targeting HFS installations exposed to the internet. Although the precise count of compromised servers is unclear, the trend indicates that adversaries are actively weaponizing the flaw instead of simply scanning for it.

Rejetto HFS is popular because of its straightforward setup, allowing users to share files over HTTP with little configuration. Yet this widespread use also draws attackers looking for easy targets. The session‑forgery bug sidesteps authentication, giving attackers the same rights as a signed‑in administrator and potentially enabling full system takeover via remote code execution.

The developer has confirmed the issue and plans to publish a patched release soon. Meanwhile, security professionals recommend that administrators install any existing updates, implement robust network segmentation, and, if possible, temporarily turn off the web interface. Additionally, watching logs for atypical session behavior and using intrusion‑detection signatures that catch the known exploit patterns can help reduce risk.

The appearance of active exploitation highlights a wider lesson for the SaaS landscape: even obscure, legacy applications need regular security updates. As threat actors keep automating scans for vulnerable services, groups using HFS should prioritize remediation to prevent becoming accidental entry points for larger cyber‑attack operations.

Source: feedburner
TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related