Back to advisories

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Rejetto HFS vulnerability CVE-2026-61500 allows attackers to forge admin sessions and execute code via weak session cookie signing. Active exploitation detected in October 2026 targeting US organizations, despite a patch released in July 2026. Any unpatched HFS instance is immediately compromised.

CRITICALAdvisoryOct 06, 2026
Action required
Identify and patch all Rejetto HFS instances to July 2026 patch level or later. Search logs for HFS access patterns and session manipulation attempts from October 2026 forward. Block HFS ports at perimeter if not actively required.
Affected products
HTTP File Server (HFS)RejettoMythosAnthropic