chiprook
← Security
SecurityOctober 4, 2026, 08:13

CVE-2026-61500 in Rejetto HFS: forged admin session and RCE without login

Rejetto HFS 3.0.0–3.2.0 carries a critical flaw (CVSS 9.8): a weak Math.random() in Koa lets attackers recover the cookie-signing key, forge an admin session and run code as root via server_code. Exploitation began October 1, 2026; HFS 3.2.1 fixes it.

CVE-2026-61500 in Rejetto HFS: forged admin session and RCE without login
#Rejetto#HFS#Horizon3.ai
Read next
Security

Anthropic's Mythos AI found a critical Rejetto HFS flaw now under active exploitation

Security

SOCRadar: AI logins stolen from 80,000+ organizations

Security

NordVPN: scammers steal Robux from children via fake Roblox login pages

Security

TrustSink: rogue external MFA provider steals passwords in Microsoft Entra logins