Attackers are actively exploiting a critical vulnerability in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, according to multiple security outlets. The flaw enables attackers to recover or predict a session-cookie signing key, allowing them to forge admin sessions. It also permits remote code execution (RCE), leading to full compromise of affected servers.

Reporting links the issue to weak pseudo-random number generation in how a signing key is produced, which can make the key predictable. SecurityWeek and Bleeping Computer describe practical exploitation outcomes such as gaining administrative access and running code remotely. The Hacker News also frames the attack as session forgery enabled by the predictable key, while noting active exploitation attempts observed in the wild.

Across the coverage, there is additional emphasis on reconnaissance and targeting behavior. Bleeping Computer reports that systems are being actively scanned for the vulnerable configuration, suggesting attackers are looking for exposed Rejetto HFS instances to exploit the flaw at scale.