[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:attackers-target-rejetto-hfs-flaw-that-enables-admin-session-forgery-and-rce-muwikdtp":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":18,"article_ids":19,"ioc_summary":21,"source_urls":22,"status":24,"expires_at":25,"created_at":26,"updated_at":27,"articles":28},"eee76b3a-175e-41d3-97ae-0a0a045ed08f","Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE","attackers-target-rejetto-hfs-flaw-that-enables-admin-session-forgery-and-rce-muwikdtp","Rejetto HFS vulnerability CVE-2026-61500 allows attackers to forge admin sessions and execute code via weak session cookie signing. Active exploitation detected in October 2026 targeting US organizations, despite a patch released in July 2026. Any unpatched HFS instance is immediately compromised.","critical","advisory",[12],"CVE-2026-61500",[14,15,16,17],"HTTP File Server (HFS)","Rejetto","Mythos","Anthropic","Identify and patch all Rejetto HFS instances to July 2026 patch level or later. Search logs for HFS access patterns and session manipulation attempts from October 2026 forward. Block HFS ports at perimeter if not actively required.",[20],"fed8746e-f0de-4680-8b91-a5f92c4dc7f9",null,[23],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fattackers-target-rejetto-hfs-flaw-that.html","active","2026-10-08T10:06:16.583+00:00","2026-10-06T10:06:22.025588+00:00","2026-10-06T10:06:34.662359+00:00",[29],{"id":20,"title":6,"url":23}]