Active scans target Rejetto HFS critical RCE flaw
๐ Researchers report active probes targeting CVE-2026-61500 in Rejetto HFS, a session-cookie signing weakness that can enable account takeover and remote code execution. Horizon3 linked discovery to Anthropic's Mythos model and released a PoC, prompting small-scale scans from a China Telecom IP. Administrators are urged to upgrade to Rejetto HFS 3.2.1 or preferably 3.3.4 to mitigate exploitation.