CVE-2026-61500
CVSS 9.8 CRITICAL: rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random()… EPSS 0.9% (57º percentile).
Vulnerabilità ed exploit
Rejetto HTTP File Server è passato in poche ore da disclosure a bersaglio reale: CVE-2026-61500 è stato sfruttato entro il giorno successivo, con tentativi osservati da IP ospitati in Cina contro host vulnerabili negli Stati Uniti e in Giappone.
La falla aggira il login. Chi la sfrutta entra nelle funzioni amministrative e può arrivare all’esecuzione di codice remoto sul server, quindi un HFS esposto su Internet smette di essere un semplice file server e diventa un punto d’ingresso nella macchina.
La correzione è v3.2.1 o successiva. Per chi usa HFS come servizio pubblico, il punto non è più solo la presenza della CVE, ma il fatto che una finestra pensata per la patch si è già chiusa quasi del tutto.
1 fonte · 5 ore fa
CVSS 9.8 CRITICAL: rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random()… EPSS 0.9% (57º percentile).
The Register Security
Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
Exploitation attempts came from China-hosted IP, VulnCheck researcher says
originalePart of the PlainSec briefing for 2026-10-03
Every edition of this story: HFS finisce sotto attacco entro un giorno dalla disclosure