Security News

New Rejetto HFS Flaw Already Under Attack, Days After Disclosure

The Register · 4 Oct 2026
Key Takeaway If your business uses Rejetto HTTP File Server, update immediately to version 3.2.1 or later to close this actively exploited security gap.

Security researchers have found a critical authentication-bypass vulnerability, tracked as CVE-2026-61500, in Rejetto HTTP File Server (HFS), a popular open-source tool used for sharing files over the web. The flaw can allow attackers to gain full administrative access and remotely execute code on vulnerable servers. HFS had already appeared on the US Cybersecurity and Infrastructure Security Agency's list of Known Exploited Vulnerabilities in 2024, highlighting a pattern of repeated real-world abuse.

The vulnerability was discovered using Anthropic's AI-powered bug-hunting tool, Mythos, and disclosed publicly along with details of how it could be exploited. Within a day, researchers at VulnCheck detected active exploitation attempts, with the first wave originating from an IP address in China and targeting servers in the US and Japan. By the following day, additional exploitation attempts were observed from US-based IP addresses believed to be routed through a proxy.

This incident underscores how quickly attackers move once technical details of a vulnerability become public, particularly when proof-of-concept exploitation steps are shared openly. Businesses running Rejetto HFS should treat this as an urgent patching priority.

vulnerability patch-management file-server-security
Primary source cisa.gov ->

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.