INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Rejetto HFS Servers Scanned for Critical RCE Flaw Exploitation
| 2026-10-05 20:20 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). The observed activity appears to be small-scale reconnaissance from a single China Telecom IP address probing deployments in Japan and the United States. This incident affects users of Rejetto HFS servers, with no reported number of affected hosts or organizations mentioned. The attack works by exploiting the vulnerability, allowing hackers to recover the session key and potentially execute custom server-side JavaScript code for remote code execution. As of now, VulnCheck has not shared details on successful exploitation or any post-exploitation activity, but users are recommended to upgrade to version 3.2.1 or the latest stable release as soon as possible.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-86060, CVE-2026-65660 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-86060CVE-2026-86060
CVE-2026-65660CVE-2026-65660
CVE-2026-67279CVE-2026-67279
CVE-2026-61500CVE-2026-61500
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
telecommunicationstelecommunications
Incident Timeline
July 13, 2026
Threat actors exploited the session-cookie signing weakness and leakage issue in Rejetto HFS version 3.2.1, which was first published on July 13, 2026, as part of a broader attack that also targeted SharePoint RCE and RouterOS flaws.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-61500
CVE-2026-61500,
first published on July 13, 2026
, is a session-cookie signing weakness and leakage issue fixed in Rejetto HFS version 3.2.1.
infrastructure
3.2.1
CVE-2026-61500,
first published on July 13, 2026
, is a session-cookie signing weakness and leakage issue fixed in Rejetto HFS version 3.2.1.
September 2, 2026
Threat actors exploited previously disclosed SharePoint Remote Code Execution (RCE) and RouterOS vulnerabilities to launch attacks in the wild.
September 11, 2026
Threat actors exploited the newly added CVE-2026-86060 vulnerability in SharePoint and RouterOS to launch a Remote Code Execution (RCE) attack.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-86060
It's worth noting that CISA
added
CVE-2026-86060 to its KEV catalog on September 11, 2026.
September 25, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog on September 25, 2026.
Click on any entity below to view its context and source!
attribution
Microsoft SharePoint
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog.
attribution
Mikrotik RouterOS
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog.
attribution
Known Exploited
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog.
tactic
T1588.006 - Vulnerabilities
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog.
Sep 26, 2026
Threat actors exploited previously disclosed SharePoint Remote Code Execution (RCE) and RouterOS vulnerabilities to launch attacks in the wild.
September 28, 2026
CISA orders federal agencies to fix the SharePoint RCE and RouterOS flaws by September 28, 2026.
Click on any entity below to view its context and source!
attribution
Federal Civilian Executive Branch
Federal Civilian Executive Branch (FCEB) agencies have time until September 28, 2026, to apply the necessary fixes.
attribution
FCEB
Federal Civilian Executive Branch (FCEB) agencies have time until September 28, 2026, to apply the necessary fixes.
September 30, 2026
Horizon3 published more details about the flaw and a proof-of-concept exploit in a write-up on September 30, 2026.
Click on any entity below to view its context and source!
organisation
PoC
Horizon3 published more details about the flaw and a proof-of-concept (PoC) exploit in a write-up on September 30, 2026.
2016, 2019
Threat actors exploited vulnerabilities in SharePoint Server 2016, 2019, and Subscription Edition to achieve Remote Code Execution (RCE) on affected servers.
Click on any entity below to view its context and source!
tactic
T1584.004 - Server
The flaw affects SharePoint Server 2016, 2019, and Subscription Edition.
2026/10/05
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500.
Click on any entity below to view its context and source!
organisation
Condon
Condon said the observed activity appears to be small-scale reconnaissance from a single China Telecom IP address probing deployments in Japan and the United States.
organisation
China Telecom IP
Condon said the observed activity appears to be small-scale reconnaissance from a single China Telecom IP address probing deployments in Japan and the United States.
organisation
Rejetto
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE).
Hackers are actively scanning for a Rejetto HFS weak signing....
organisation
HFS
Recovering the session key
Source: Horizon3
The researchers' exploit demonstrates the chain to abuse HFS's built-in ability to execute custom server-side JavaScript to achieve remote code execution.
infrastructure
Windows
Rejetto HFS (HTTP File Server) is a free and
open-source
file-sharing server tool used for self-hosted file sharing on Windows, Linux, and macOS.
"As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability," the Windows maker
noted
.
infrastructure
Linux
Rejetto HFS (HTTP File Server) is a free and
open-source
file-sharing server tool used for self-hosted file sharing on Windows, Linux, and macOS.
infrastructure
Macos
Rejetto HFS (HTTP File Server) is a free and
open-source
file-sharing server tool used for self-hosted file sharing on Windows, Linux, and macOS.
organisation
Microsoft
As
reported
by The Hacker News earlier this week, CVE-2026-65660 was originally described by Microsoft as a
spoofing vulnerability
impacting SharePoint Server.
infrastructure
3.2.1
Users of Rejetto HFS are recommended to upgrade to version 3.2.1 or, ideally, the latest stable release, 3.3.4, as soon as possible.
infrastructure
3.3.4
Users of Rejetto HFS are recommended to upgrade to version 3.2.1 or, ideally, the latest stable release, 3.3.4, as soon as possible.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
infrastructure
Microsoft Office
A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
organisation
Microsoft Office SharePoint
A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
organisation
CVE-2026-67279
CVE-2026-67279
(CVSS score: 6.9) -
organisation
KEV
The second vulnerability to be added to the KEV catalog is CVE-2026-67279, which has been chained along with CVE-2026-86060, an argument injection flaw in the RouterOS login process, as part of an exploit codenamed
MikroTrick
.
organisation
CVE-2026
"CVE-2026-67279 allowed an unauthenticated client to create a session channel, while CVE-2026-86060 allowed it to supply login with an attacker-controlled policy mask.
organisation
MikroTik RouterOS
The second flaw added to the catalog, tracked as
CVE-2026-67279
(CVSS score of 6.9), is an SSH protocol flaw in MikroTik RouterOS that allows an unauthenticated attacker to bypass the normal authentication flow, open a session channel and execute commands, potentially creating or modifying files on the device.
SharePoint RCE and MikroTik RouterOS
An improper enforcement of behavioral workflow vulnerability in Mikrotik RouterOS that could allow an unauthenticated client to open a session channel and send an exec request.
organisation
SSH
The second flaw added to the catalog, tracked as
CVE-2026-67279
(CVSS score of 6.9), is an SSH protocol flaw in MikroTik RouterOS that allows an unauthenticated attacker to bypass the normal authentication flow, open a session channel and execute commands, potentially creating or modifying files on the device.
organisation
SharePoint RCE
SharePoint RCE and MikroTik RouterOS
data_breach
2 September
CERT Polska reported successful attacks against internet-exposed RouterOS devices dating back to at least September 2, 2026, with attackers using the MikroTrick chain.
organisation
MikroTrick
"MikroTrick combines two failures at different trust boundaries," security researcher Emilio Gallegos
said
.
organisation
RouterOS
"The first allows an unauthenticated connection to reach functionality that RouterOS should expose only after login.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Rejetto HFS (HTTP File Server) is a free and
open-source
file-sharing server tool used for self-hosted file sharing on Windows, Linux, and macOS.
"As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability," the Windows maker
noted
.
Metrics
infrastructure
Linux
Affected Product
Rejetto HFS (HTTP File Server) is a free and
open-source
file-sharing server tool used for self-hosted file sharing on Windows, Linux, and macOS.
Metrics
infrastructure
Macos
Affected Product
Rejetto HFS (HTTP File Server) is a free and
open-source
file-sharing server tool used for self-hosted file sharing on Windows, Linux, and macOS.
Metrics
infrastructure
3.2.1
Software Version
CVE-2026-61500,
first published on July 13, 2026
, is a session-cookie signing weakness and leakage issue fixed in Rejetto HFS version 3.2.1.
Users of Rejetto HFS are recommended to upgrade to version 3.2.1 or, ideally, the latest stable release, 3.3.4, as soon as possible.
Metrics
infrastructure
3.3.4
Software Version
Users of Rejetto HFS are recommended to upgrade to version 3.2.1 or, ideally, the latest stable release, 3.3.4, as soon as possible.
Metrics
infrastructure
Microsoft Office
Affected Product
A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
Metrics
data_breach
2
September
CERT Polska reported successful attacks against internet-exposed RouterOS devices dating back to at least September 2, 2026, with attackers using the MikroTrick chain.
Intelligence Sources
The Hacker News
2026-09-26
Security Affairs
2026-09-25
Mastodon BleepingComputer
2026-10-05
Hackers are actively scanning for a Rejetto HFS weak signing...
Mastodon BleepingComputer
BleepingComputer
2026-10-05
Rejetto HFS servers now actively scanned for critical RCE flaw
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T09:24
Comprehensive Tactical Telemetry
Highly Correlated Entities
17x
organisation
Identified Entity
Condon
entity
15x
attribution
Attributing Entity
Flaws Actively Exploited
authority
10x
timeline
Temporal Reference
July 13, 2026
date
4x
vulnerability
Exploited CVE
CVE-2026-61500
cve
4x
infrastructure
Affected Product
Windows
software
3x
target region
Target Country
China
country
3x
tactic
Cyber Operation Type
Reconnaissance
tactic
3x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
2x
infrastructure
Software Version
3.2.1
version
2x
vulnerability
CVSS Score
9
score
Contextual Telemetry
Context Block
7 METRICS
general metric
Cve-2026
61,500
cve-2026
general metric
Score
9
score
general metric
Cvss Score
7
cvss score
general metric
Sep
26
sep
source region
Origin Country
Poland
country
general metric
Improper Enforcement
65,660
improper enforcement
data breach
September
2
september
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.