CVE-2026-61500
CVSS 9.8 CRITICAL: rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random()… EPSS 1.0% (61st percentile).
Vulnerabilities · 9h ago
INCIBE-CERT says Rejetto HFS 3.0.0 through 3.2.0 has a critical flaw, CVE-2026-61500, and Horizon3.ai reported active exploitation. The bug affects Internet-facing HFS instances that use the vulnerable session-signing logic.
HFS uses a non-cryptographic pseudo-random number generator to make the secret that signs admin cookies, and its login flow leaks output from that same generator. With enough leaked values, an unauthenticated attacker can reconstruct the signing key, forge an admin session, and reach HFS admin functions that can run code on the server.
The lasting exposure is bigger than a bad cookie: any exposed HFS host in the affected range can be treated as a potential full-server compromise if that key can be rebuilt. For operators using HFS as a public file-transfer or download service, the trust boundary sits at the session layer until 3.2.1 or later is in place.
CVSS 9.8 CRITICAL: rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random()… EPSS 1.0% (61st percentile).
1 source covering this story
Uso de generador pseudoaleatorio criptográficamente débil en HFS de Rejetto
Zach Hanley, de Horizon3.ai, ha informado sobre una vulnerabilidad de severidad crítica que, en caso d
Part of the PlainSec briefing for 2026-10-06