Critical CVE-2026-61500 in Rejetto HFS Allows Admin Session Forgery Leading to Remote Code Execution
A critical vulnerability identified as CVE-2026-61500 is being actively exploited in Rejetto HTTP File Server (HFS), allowing remote attackers to forge administrator sessions and achieve remote code execution without authentication.
The issue affects HFS versions 3.0.0 to 3.2.0 inclusive and has been fixed in version 3.2.1. Security teams are urged to prioritize updates for any instances exposed to the internet, as the flaw carries a CVSS 4.0 score of 9.3 and a CVSS 3.1 score of 9.8, and is associated with CWE-338 (use of a cryptographically weak PRNG).
The root cause stems from how HFS generates the signing key for session cookies. Instead of using a cryptographically secure random number generator, the software relies on JavaScript Math.random(), which is intended for general-purpose use rather than security applications. The login flow exposes enough outputs from this generator that a patient attacker can reconstruct its internal state after observing only a few responses.
With the reconstructed state, the attacker can forge valid session cookies granting full administrator privileges. From there, the attacker can abuse the server_code configuration option to execute arbitrary JavaScript on the server side, turning session forgery into a straightforward case of remote code execution.
A Python proof-of-concept exploit was publicly released in late September 2026. On October 1, 2026, exploitation attempts were detected against vulnerable systems in the United States, with activity linked to an unidentified actor operating from China.
Administrators should immediately update to HFS 3.2.1 or later. Prior to patching, organizations are advised to identify all internet-facing instances running versions 3.0.0–3.2.0, restrict administrative interfaces to trusted networks, implement network segmentation, and monitor logs for suspicious activity involving the get_config and set_config endpoints.
As a temporary mitigation, administrators may configure robust signing keys via COOKIE_SIGN_KEYS, although this does not replace the official patch. In cases of suspected compromise, simply applying the update is insufficient; credentials must be rotated, system integrity verified, and configuration changes reviewed.
Related articles
Dell Patches Six Critical Flaws in Container Storage Modules for Kubernetes
Dell has fixed six vulnerabilities in its Container Storage Modules that integrate storage systems with Kubernetes clusters. Two of the issues received the maximum CVSS score of 10.0, allowing remote unauthenticated attackers to obtain full administrative credentials for registered storage backends. Additional flaws enable privilege escalation to root on cluster nodes, exposure of hardcoded credentials, and leakage of Kubernetes secrets across the entire cluster. All versions prior to 1.17.0 are affected, with the fixes delivered in version 1.18.0. No workarounds exist, and Dell recommends rotating JWT signing keys after applying the update because the previous keys must be considered compromised.
Critical Sandbox Bypass Flaw in GitLab AI Gateway Enables Remote Command Execution
GitLab has released patches for a critical vulnerability in its GitLab AI Gateway component that allows authenticated users to bypass sandbox restrictions and execute arbitrary commands. The flaw, tracked as CVE-2026-90970, resides in the custom flow prompt template processing of the Duo Agent Platform and carries a CVSS v3.1 base score of 9.9. Self-hosted deployments are affected, while GitLab’s own hosted AI Gateway service has already been updated. The company urges immediate upgrades to versions 19.4.1, 19.3.2, or 19.2.4. The vulnerability can be triggered under specific conditions by users with access to the Duo Agent Platform through crafted flow configurations.
WebPros Releases Critical Patches for Three Vulnerabilities in cPanel & WHM
WebPros International has published security updates addressing three critical vulnerabilities in its cPanel & WHM hosting management platform. All three issues received the highest severity rating of Critical. The flaws include CVE-2026-93698, an input validation weakness in the Multilang adminbin component that could allow root-level operating system command execution. Two additional stored cross-site scripting vulnerabilities were also fixed, one of which is CVE-2026-93697 affecting the Mass Modify Accounts interface in WHM. Successful exploitation of the XSS flaws could let low-privileged accounts hijack administrator sessions. The updates were made available on September 29, 2026, and carry CVSS v3.0 base scores reaching 9.9.
Top Cybersecurity Stories: SharePoint Exploits Warned by US Authorities, Citrix and WordPress Flaws Lead Weekly Rankings
Security NEXT has published its weekly ranking of the most viewed articles from September 27 to October 3, 2026, highlighting critical vulnerability disclosures and confirmed exploitation cases. US authorities issued warnings about active exploitation of five vulnerabilities affecting SharePoint and WordPress. Citrix NetScaler received multiple vulnerability advisories with two flaws already confirmed as exploited in the wild. Apple released iOS 26.7.1 to address vulnerabilities potentially used in targeted attacks against specific individuals. Other notable incidents include a personal data breach at Times Car car-sharing service and a ransomware attack impacting Keio Electric Railway operations.