Hackers actively scanning Rejetto HFS servers for CVE-2026-61500
Threat actors are targeting Rejetto HFS deployments in the U.S. and Japan following the public release of exploit details for a critical vulnerability.
Hackers have begun actively scanning for the CVE-2026-61500 vulnerability in Rejetto HFS servers following the recent publication of exploit details. According to BleepingComputer, security researchers at VulnCheck have observed reconnaissance activity originating from a single IP address, specifically targeting server deployments located in Japan and the United States.
To mitigate the risk posed by this flaw, users are advised to update their software to Rejetto HFS version 3.2.1 or the latest stable release, version 3.3.4.
The vulnerability, identified as CVE-2026-61500, was first published on July 13, 2026. It was initially patched in Rejetto HFS version 3.2.1. However, interest in the flaw intensified after Horizon3 published a technical write-up and a proof-of-concept exploit for the vulnerability on September 30, 2026.
Quick answers
What is the recommended version to patch CVE-2026-61500?
Users should update to Rejetto HFS version 3.2.1 or the latest stable version 3.3.4.
Where are the attacks being observed?
VulnCheck has observed reconnaissance activity targeting Rejetto HFS deployments in Japan and the United States.