System running
Last check: 2026-09-29 00:26:08 | Auto-updates every hour
754 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-CVE-2026-61500

Severity
CRITICAL
CVSS Score
9.8
Description

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature....

PoCs for CVE-CVE-2026-61500

CVE-2026-61500
RCE Python 0
aramosf 2026-09-26
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources