# Attackers probe Rejetto HFS flaw that enables administrator session forgery

_Published Monday, October 5, 2026 at 4:38 PM EDT · Security · Latest · Tier 2 — Notable_

![Attackers probe Rejetto HFS flaw that enables administrator session forgery — Primary](https://www.bleepstatic.com/content/hl-images/2025/11/05/Credit-card-hacker.jpg)

VulnCheck has observed probes targeting a Rejetto HFS vulnerability that can let attackers forge administrator sessions and execute code on file-sharing servers, BleepingComputer reported. The activity appears to be small-scale reconnaissance from a single China Telecom IP address targeting deployments in Japan and the United States.

The flaw, CVE-2026-61500, affects versions 3.0.0 through 3.2.0. Login responses expose outputs from the same weak random-number generator used to create session-signing keys, allowing attackers to recover a key and forge an administrator cookie. HFS can then execute attacker-controlled server-side JavaScript.

Version 3.2.1 fixes the vulnerability. VulnCheck has not shared evidence of successful exploitation or activity following a compromise.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/)

---
Canonical: https://techandbusiness.org/newswire/IpwK4fAIf_ULpTkwWXWUQW
Published: 2026-10-05T20:38:02.971Z
Story chronology: 2026-10-05T20:20:05.000Z
Retrieved: 2026-10-05T23:44:32.101Z
Publisher: Tech & Business (techandbusiness.org)
