Ai-Discovered
CVE-2026-61500: Rejetto HFS Predictable Session Key Gives Unauthenticated Admin and RCE, Probed Within a Day
Rejetto HFS 3.x signs sessions with a key derived from Math.random() and leaks its outputs at login, letting unauthenticated attackers forge admin sessions and run server-side JavaScript; scanning from China began October 1.