MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-05 · via The Hacker News

Critical Rejetto File Server Vulnerability Under Active Exploitation for Unauthorized Access

Image via The Hacker News
Image via The Hacker News

A severe vulnerability in Rejetto HTTP File Server exploiting a weak random number generator is being actively targeted by attackers in the wild. The flaw, rated 9.3 on the CVSS scale, allows adversaries to forge administrative sessions and execute arbitrary code on affected systems. VulnCheck researchers have documented ongoing exploitation attempts leveraging this critical weakness.

Expanded Detail

The vulnerability affects Rejetto HTTP File Server, a file-sharing application that organizations use to distribute and manage documents across networks. The flaw stems from a deficient random number generation mechanism, which undermines the cryptographic security of session tokens. This weakness enables attackers to predict and replicate administrative credentials without possessing legitimate access rights.

Security researchers at VulnCheck have observed active attacks exploiting this flaw in real-world environments. The high CVSS severity rating reflects the danger posed by the combination of session hijacking and arbitrary code execution capabilities, which could allow attackers to take complete control of vulnerable servers and the data they contain.

Context

Organizations running unpatched instances of Rejetto HTTP File Server may face significant risk, as attackers could potentially compromise sensitive files and establish persistent access to internal systems. Users in government, enterprise, and educational sectors who rely on this software could be particularly vulnerable. Timely patching and network monitoring may help mitigate exposure, though the active exploitation suggests some systems may already be compromised before administrators can respond.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
Fortinet Issues Critical Patch for FortiMail Flaw Allowing Unauthorized File Creation · Cybersecurity
Critical vulnerability in Dell's update tool allows remote root access on servers · Cybersecurity
Active Exploitation Reported for Citrix NetScaler SAML Authentication Vulnerability · Cybersecurity
Citrix releases emergency patches for actively exploited NetScaler vulnerability · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE.” Browse more stories.