China-based actor targets U.S. Rejetto HFS servers through a forgeable admin cookie
VulnCheck says a China-based actor began targeting vulnerable U.S. Rejetto HFS servers on October 1, exploiting CVE-2026-61500 to forge admin sessions. The fix shipped in July as version 3.2.1. Exposed instances that have not updated are reachable now.
Perspective Coverage
4 publishers- Builder
- Builder 43%
- Operator
- Operator 47%
- Investor
- Investor 10%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+30
- Incentives50
- Confidence60