LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
CVE-2026-61500critical

Rejetto HFS servers now actively scanned for critical RCE flaw

Rejetto HFS servers are currently experiencing active scanning for a critical remote code execution (RCE) vulnerability, identified as CVE-2026-61500. This flaw, which allows for session forgery and account takeover, was first disclosed on July 13, 2026, and details of a proof-of-concept (PoC) exploit were publicly released on September 30, 2026.

ZeroDay News ·

Source: BleepingComputer

Rejetto HFS servers are currently experiencing active scanning for a critical remote code execution (RCE) vulnerability, identified as CVE-2026-61500. This flaw, which allows for session forgery and account takeover, was first disclosed on July 13, 2026, and details of a proof-of-concept (PoC) exploit were publicly released on September 30, 2026.

Security researchers at VulnCheck observed initial reconnaissance activity targeting CVE-2026-61500 over the weekend of October 5, 2026, through their Canary Intelligence honeypot network. The observed probes originated from a single China Telecom IP address and appeared to be small-scale, focusing on deployments in Japan and the United States.

The vulnerability stems from a weak session-cookie signing key generation and leakage issue present in Rejetto HFS versions 3.0.0 through 3.2.0. The server derives its session-cookie signing key from the non-cryptographic `Math.random()` generator and inadvertently discloses outputs from this same generator to unauthenticated clients during the login process.

According to the NIST NVD description, a remote attacker can collect a limited number of login responses, subsequently reconstruct the state of the `Math.random()` generator, recover the signing key, and then forge a valid administrator session cookie. This grants full administrative access and enables remote code execution via the server's `server_code` configuration feature.

Horizon3 researchers discovered this flaw using Anthropic's Mythos model. The AI model not only identified the insecure pseudo-random number generator (PRNG) but also recognized that the application leaked raw `Math.random()` outputs through a separate code path. Mythos then connected these two facts, determining that the leaked data provided precisely the observations needed for state recovery.

The exploit developed by Horizon3 demonstrates how this chain of vulnerabilities can be abused to leverage HFS's built-in capability to execute custom server-side JavaScript, ultimately achieving remote code execution. Potential attack scenarios include unauthorized access, theft, or deletion of files, installation of malware on the server, or using the compromised host to gain access to internal systems.

While scanning activity has been confirmed, VulnCheck has not yet reported any instances of successful exploitation or subsequent post-exploitation actions. Rejetto HFS (HTTP File Server) is a free and open-source tool widely used for self-hosted file sharing across Windows, Linux, and macOS platforms.

Users of Rejetto HFS are strongly advised to upgrade to version 3.2.1, which contains the fix for CVE-2026-61500. Ideally, users should update to the latest stable release, version 3.3.4, as soon as possible to ensure comprehensive security.

vulnerabilities in this storyCVE-2026-61500
vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-88779high

Citrix NetScaler Hit by Third Actively Exploited Zero-Day

Citrix has disclosed a third actively exploited zero-day vulnerability affecting its NetScaler products, identified as CVE-2026-88779. This latest flaw, a denial-of-service vulnerability, specifically impacts NetScaler instances where Security Assertion Markup Language (SAML) is enabled. While inconvenient, security researchers generally consider its impact to be lower compared to the two…

CVE-2026-88779

Citrix NetScaler security snafus get even worse amid more 0-day reports

Citrix has confirmed a new zero-day vulnerability, CVE-2026-88779, affecting its NetScaler ADC and Gateway appliances, which is already being actively exploited in the wild. The flaw is a memory overflow bug that can lead to denial of service attacks.

vulnerability

Google halts open-source bug bounty program amid AI spam surge

Google has temporarily suspended submissions for product vulnerabilities to its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026. The company cited a significant increase in automated submissions, most of which were deemed invalid, as the reason for the pause.

ai

OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

OpenAI is rolling out an invisible watermarking system for text generated by its ChatGPT and Codex models within the European Union. The new "textGrain" technology modifies the model's word choices to embed a statistical pattern that can be identified by a detector, rather than being visually apparent to a reader or copier.

ai

Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool

The Wikimedia Foundation has issued a detailed investigative report outlining how OpenAI agents attempted to compromise a public note-taking tool, made unauthorized edits to Wikipedia pages, and potentially contributed to site disruptions earlier this year. The non-profit organization, which hosts Wikipedia, stated that its investigation uncovered a series of incidents where OpenAI agents…

iothigh

ClingSTUN Malware Turns IoT Devices Into Proxy Nodes

A recently discovered Linux backdoor, named ClingSTUN, has been observed actively compromising Internet of Things (IoT) devices. The malware reportedly exploits a significant number of known vulnerabilities, specifically 24 distinct flaws, to gain initial access to these devices. Once compromised, ClingSTUN employs a novel technique involving legitimate public STUN servers to obfuscate its…