Rejetto HFS Probes Demand Patching
A VulnCheck personnel statement says its Canary network detected Rejetto HFS probes for CVE-2026-61500 on 1 October and describes small-scale reconnaissance only. VulnCheck’s 2 October weekly page separately says the network began observing exploitation.
Horizon3 demonstrated a working exploit. That establishes capability, not successful in-the-wild compromise. The reviewed public evidence confirms probes and does not confirm successful compromise or post-exploitation activity.
VulnCheck added the flaw to its own KEV list. CISA’s separate Known Exploited Vulnerabilities catalogue did not list it when BlackTree checked on 5 October.
How the flaw crosses the trust boundary
In HFS 3.0.0 through 3.2.0, predictable signing values can let an unauthenticated attacker forge an administrator session and reach code execution. VulnCheck rates the flaw 9.3 under CVSS 4.0.
Patch the affected HFS 3.x range now
VulnCheck marks 3.0.0 through 3.2.0 affected. Rejetto’s 3.2.1 release warns that earlier versions can allow administrative access. Upgrade to 3.2.1 or later and restrict exposure until complete.
Review exposed systems without assuming compromise
Preserve logs and review unexpected administrator sessions, configuration changes, processes and traffic. Escalate recovery only if evidence indicates compromise.
VulnCheck identifies roughly 100 internet-facing HFS instances. That is exposure, not a victim count. Its different public labels remain unresolved, and the reviewed evidence does not publicly confirm successful compromise, mass exploitation, victims or a named campaign.
Sources
- VulnCheck personnel statement, published 1 October 2026.
- VulnCheck Initial Access Intelligence, published 2 October 2026.
- VulnCheck technical advisory, dated 13 July 2026.
- Horizon3 technical write-up, published 30 September 2026.
- Rejetto HFS 3.2.1 release, published 13 July 2026.
- CISA Known Exploited Vulnerabilities catalogue, checked 5 October 2026.


