Critical Rejetto File Server Vulnerability Under Active Exploitation for Unauthorized Access

A severe vulnerability in Rejetto HTTP File Server exploiting a weak random number generator is being actively targeted by attackers in the wild. The flaw, rated 9.3 on the CVSS scale, allows adversaries to forge administrative sessions and execute arbitrary code on affected systems. VulnCheck researchers have documented ongoing exploitation attempts leveraging this critical weakness.
The vulnerability affects Rejetto HTTP File Server, a file-sharing application that organizations use to distribute and manage documents across networks. The flaw stems from a deficient random number generation mechanism, which undermines the cryptographic security of session tokens. This weakness enables attackers to predict and replicate administrative credentials without possessing legitimate access rights.
Security researchers at VulnCheck have observed active attacks exploiting this flaw in real-world environments. The high CVSS severity rating reflects the danger posed by the combination of session hijacking and arbitrary code execution capabilities, which could allow attackers to take complete control of vulnerable servers and the data they contain.
Organizations running unpatched instances of Rejetto HTTP File Server may face significant risk, as attackers could potentially compromise sensitive files and establish persistent access to internal systems. Users in government, enterprise, and educational sectors who rely on this software could be particularly vulnerable. Timely patching and network monitoring may help mitigate exposure, though the active exploitation suggests some systems may already be compromised before administrators can respond.