INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Rejetto HFS Servers Scanned for Critical RCE Flaw Exploitation

| 2026-10-05 20:20 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). The observed activity appears to be small-scale reconnaissance from a single China Telecom IP address probing deployments in Japan and the United States. This incident affects users of Rejetto HFS servers, with no reported number of affected hosts or organizations mentioned. The attack works by exploiting the vulnerability, allowing hackers to recover the session key and potentially execute custom server-side JavaScript code for remote code execution. As of now, VulnCheck has not shared details on successful exploitation or any post-exploitation activity, but users are recommended to upgrade to version 3.2.1 or the latest stable release as soon as possible.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-86060, CVE-2026-65660 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-86060CVE-2026-86060 CVE-2026-65660CVE-2026-65660 CVE-2026-67279CVE-2026-67279 CVE-2026-61500CVE-2026-61500
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment telecommunicationstelecommunications
Incident Timeline
‎July 13, 2026
Threat actors exploited the session-cookie signing weakness and leakage issue in Rejetto HFS version 3.2.1, which was first published on July 13, 2026, as part of a broader attack that also targeted SharePoint RCE and RouterOS flaws.
vulnerability CVE-2026-61500
infrastructure 3.2.1
‎September 2, 2026
Threat actors exploited previously disclosed SharePoint Remote Code Execution (RCE) and RouterOS vulnerabilities to launch attacks in the wild.
‎September 11, 2026
Threat actors exploited the newly added CVE-2026-86060 vulnerability in SharePoint and RouterOS to launch a Remote Code Execution (RCE) attack.
vulnerability CVE-2026-86060
‎September 25, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog on September 25, 2026.
attribution Microsoft SharePoint
attribution Mikrotik RouterOS
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎Sep 26, 2026
Threat actors exploited previously disclosed SharePoint Remote Code Execution (RCE) and RouterOS vulnerabilities to launch attacks in the wild.
‎September 28, 2026
CISA orders federal agencies to fix the SharePoint RCE and RouterOS flaws by September 28, 2026.
attribution Federal Civilian Executive Branch
attribution FCEB
‎September 30, 2026
Horizon3 published more details about the flaw and a proof-of-concept exploit in a write-up on September 30, 2026.
organisation PoC
‎2016, 2019
Threat actors exploited vulnerabilities in SharePoint Server 2016, 2019, and Subscription Edition to achieve Remote Code Execution (RCE) on affected servers.
tactic T1584.004 - Server
‎2026/10/05
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500.
organisation Condon
organisation China Telecom IP
organisation Rejetto
organisation HFS
infrastructure Windows
infrastructure Linux
infrastructure Macos
organisation Microsoft
infrastructure 3.2.1
infrastructure 3.3.4
organisation NFL
organisation CHANEL
infrastructure Microsoft Office
organisation Microsoft Office SharePoint
organisation CVE-2026-67279
organisation KEV
organisation CVE-2026
organisation MikroTik RouterOS
organisation SSH
organisation SharePoint RCE
data_breach 2 September
organisation MikroTrick
organisation RouterOS
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎3.2.1
Software Version
Metrics
infrastructure
‎3.3.4
Software Version
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
data_breach
2
September
Intelligence Sources