Skip to content
See the World Through ScienceA project of ALLATRA

A File-Server Flaw Fixed in July Is Now Being Exploited, VulnCheck Says

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

An early black NeXT desktop computer and its monitor on display, with a handwritten paper note taped to the machine saying that it is a server and must not be powered down.
The NeXT machine that ran the world's first web server, kept at CERN in Geneva with its handwritten warning not to switch it off (illustrative)."First Web Server" by User:Coolcaesar at en.wikipedia, via wikimedia, CC-BY-SA-3.0

A critical flaw in Rejetto HFS, open-source software for sharing files from a computer over the web, is now being exploited, according to VulnCheck, the company that assigned the flaw its identifier. VulnCheck revised its record for CVE-2026-61500 on Oct. 1, and its advisory page now states that the entry is in the VulnCheck KEV database, the firm's catalog of vulnerabilities it has seen used in attacks.

For anyone still running an older version, the number to look for is 3.2.1. Everything from 3.0.0 up to but not including that release is affected, and the record names the 3.2.1 release notes as the patch. The weakness sits in the way the server signs the cookies that keep a user logged in. The advisory says a remote attacker who has never logged in can end up holding a session the server treats as the administrator's, which amounts to full administrative access.

VulnCheck's advisory rates the flaw critical and scores it 9.3 out of 10 on CVSS, the scale used to rank severity. The flaw was first made public on July 13, 2026, almost three months before the exploitation listing.

The exploitation listing is VulnCheck's own catalog, separate from the Known Exploited Vulnerabilities list kept by the US Cybersecurity and Infrastructure Security Agency. A CISA assessment attached to the same record in July still lists exploitation as none.

The record credits the finding to Zach Hanley of Horizon3.ai, in collaboration with Claude and Anthropic Research.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

A File-Server Flaw Fixed in July Is Now Being Exploited, VulnCheck Says

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.