A File-Server Flaw Fixed in July Is Now Being Exploited, VulnCheck Says

A critical flaw in Rejetto HFS, open-source software for sharing files from a computer over the web, is now being exploited, according to VulnCheck, the company that assigned the flaw its identifier. VulnCheck revised its record for CVE-2026-61500 on Oct. 1, and its advisory page now states that the entry is in the VulnCheck KEV database, the firm's catalog of vulnerabilities it has seen used in attacks.
For anyone still running an older version, the number to look for is 3.2.1. Everything from 3.0.0 up to but not including that release is affected, and the record names the 3.2.1 release notes as the patch. The weakness sits in the way the server signs the cookies that keep a user logged in. The advisory says a remote attacker who has never logged in can end up holding a session the server treats as the administrator's, which amounts to full administrative access.
VulnCheck's advisory rates the flaw critical and scores it 9.3 out of 10 on CVSS, the scale used to rank severity. The flaw was first made public on July 13, 2026, almost three months before the exploitation listing.
The exploitation listing is VulnCheck's own catalog, separate from the Known Exploited Vulnerabilities list kept by the US Cybersecurity and Infrastructure Security Agency. A CISA assessment attached to the same record in July still lists exploitation as none.
The record credits the finding to Zach Hanley of Horizon3.ai, in collaboration with Claude and Anthropic Research.
