1 post
A weak Math.random() session key in Rejetto HFS 3.0.0-3.2.0 lets attackers forge admin cookies and run code; CVE-2026-61500 is under active exploitation.