MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-05 · via BleepingComputer

Hackers Actively Probing File Servers for Exploitable Cryptographic Weakness

Image via BleepingComputer
Image via BleepingComputer

Security researchers detected active reconnaissance probes targeting CVE-2026-61500, a critical vulnerability in Rejetto HFS file-sharing software that enables attackers to forge administrator sessions and execute remote code. The flaw stems from the use of a weak non-cryptographic random number generator for session cookie signing, which was discovered using AI analysis and disclosed with proof-of-concept code in late September 2026. Early scanning activity appears to originate from China, targeting deployments in Japan and the United States following public release of technical exploitation details.

Expanded Detail

The vulnerability affects Rejetto HFS versions 3.0.0 through 3.2.0 and was initially disclosed in mid-July 2026. Security researchers from Horizon3 leveraged artificial intelligence technology to identify not just a flawed random number generator used for session authentication, but also a separate code path that inadvertently exposed the generator's outputs to unauthenticated users—creating a complete exploitation chain that attackers could weaponize.

The flaw carries particular risk because HFS includes built-in functionality allowing custom server-side scripting execution. Once an attacker forges administrative credentials, they gain access to this feature, enabling them to run arbitrary code directly on the compromised system. Organizations running outdated versions remain exposed to file theft, malware installation, and lateral movement into internal networks.

Context

This disclosure illustrates mounting pressure on administrators to maintain rapid patch cycles as exploitation timelines accelerate. Organizations deploying older HFS versions in production environments—particularly those managing sensitive files—face elevated compromise risk following public technical details becoming available. The geographic pattern of probing activity suggests targeted reconnaissance rather than indiscriminate attacks, though this distinction may prove temporary if exploit tools become widely accessible. Smaller enterprises and individuals using HFS for legitimate file-sharing purposes may lack resources to prioritize updates quickly.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Critical Rejetto File Server Vulnerability Under Active Exploitation for Unauthorized Access · Cybersecurity
Active Exploitation Reported for Citrix NetScaler SAML Authentication Vulnerability · Cybersecurity
Critical vulnerability in Dell's update tool allows remote root access on servers · Cybersecurity
Attackers Weaponize Realtek SDK Flaw to Deploy Botnet Using Novel C2 Protocol · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Rejetto HFS servers now actively scanned for critical RCE flaw.” Browse more stories.