CVE-2026-61500
Patch status
No official fix confirmed yet
Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.
Description
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Intelligence timeline
Developments from the last 30 days, newest first.
- CVSS scoredUpdate
CVE-2026-61500 scored CVSS 9.3
Basis: NIST National Vulnerability Database
Coverage
We have not published a story about this vulnerability yet.
