Active Exploits Target Critical Flaw in Rejetto HTTP File Server, Researchers Warn
Security researchers at VulnCheck have observed active exploitation attempts against a newly disclosed vulnerability in Rejetto HTTP File Server (HFS), a lightweight web‑based file‑sharing application used by small businesses and hobbyist sites worldwide.
The flaw, catalogued as CVE‑2026‑61500, carries a CVSS rating of 9.3, indicating a critical level of risk. It stems from the server's reliance on a weak pseudo‑random number generator to create session identifiers. Attackers can predict or forge these identifiers, allowing them to hijack an administrator's session and subsequently execute arbitrary code on the compromised host.
VulnCheck’s telemetry shows a surge in scanning activity and exploit payloads directed at internet‑exposed HFS instances. While the exact number of compromised servers remains unknown, the pattern suggests that threat actors are actively weaponizing the vulnerability rather than merely probing for it.
Rejetto HFS has long been favored for its simplicity, enabling users to serve files over HTTP with minimal configuration. However, its popularity also makes it an attractive target for attackers seeking low‑hanging fruit. The session‑forgery issue effectively bypasses authentication, granting attackers the same privileges as a logged‑in administrator, which can lead to full system compromise through remote code execution.
The vendor has acknowledged the problem and is expected to release a patched version shortly. In the meantime, security experts advise administrators to apply any available updates, enforce strong network segmentation, and consider temporarily disabling the web interface if it is not essential. Monitoring logs for unusual session activity and employing intrusion‑detection signatures that flag the known exploit patterns can also mitigate risk.
The emergence of active exploitation underscores a broader lesson for the software‑as‑a‑service ecosystem: even niche, legacy tools must be kept current with security patches. As attackers continue to automate scans for vulnerable services, organizations that rely on HFS are urged to prioritize remediation to avoid becoming inadvertent footholds for broader cyber‑attack campaigns.
Comments (0)
Be the first to comment.
Join the discussion