What is CVE-2026-61500?
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature.
Timeline
- 2026-07-13Published to the U.S. National Vulnerability Database (NVD)
- 2026-07-15NVD record last updated
- 2026-10-06First covered in a defend.network daily briefing
Affected product
See advisory
Remediation Steps
- Apply the latest security update for Rejetto HFS from the vendor immediately
- If patching is delayed, restrict network access to the HFS service to trusted internal networks only
- Monitor logs for unauthorized session activity or access attempts
- Rotate credentials for any accounts that may have been accessed via this vulnerability
- Scan systems for indicators of compromise (RCE artifacts, unauthorized admin accounts)
References
Referenced in our briefings & reports
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.