RC RANDOM CHAOS

exploitation

1 post

Math.random() session key lets attackers run code on HFS
Article

Math.random() session key lets attackers run code on HFS

A weak Math.random() session key in Rejetto HFS 3.0.0-3.2.0 lets attackers forge admin cookies and run code; CVE-2026-61500 is under active exploitation.