ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • Online store
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Online store
  • Posts
    • All posts
    • Categories
    • Tags
    • Statuses
  • Solutions
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Web Emergency
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • SPF, DKIM & DMARC
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

CVE-2026-61500: Rejetto HFS Under Attack — What Sysadmins in Spain Must Do Now

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. CVE-2026-61500: Rejetto HFS Under Attack — Wh...
  • All articles
  • Categories
  • Tags
  • Statuses

CVE-2026-61500: Rejetto HFS Under Attack — What Sysadmins in Spain Must Do Now

A critical flaw in Rejetto HFS is being exploited in the wildSystem administrators across Catalonia and the rest of Spain are once again reminded that...

A critical flaw in Rejetto HFS is being exploited in the wild

System administrators across Catalonia and the rest of Spain are once again reminded that even lightweight file servers can become a gateway to full compromise. Rejetto HTTP File Server (HFS), a tool often chosen for its simplicity, is affected by a critical vulnerability tracked as CVE-2026-61500. The flaw allows an unauthenticated remote attacker to forge an administrator session and, from there, execute arbitrary code on the server. Exploitation attempts have already been observed against internet-facing instances, making patching a priority rather than a routine task.

Cracked padlock on a circuit board symbolising a critical server vulnerability and the risk of remote code execution

How the vulnerability works

The root cause lies in how HFS generates the key used to sign session cookies. Instead of relying on a cryptographically secure generator, the software uses JavaScript Math.random(), a general-purpose PRNG that was never designed for security. During the login flow, enough output from that generator is exposed for a patient attacker to reconstruct its internal state after observing a small number of responses. Once the state is known, the signing key is no longer a secret.

From that point, the attack chain unfolds almost automatically. With a forged administrator session, the attacker can reach configuration options that enable server-side JavaScript execution. The server_code functionality effectively turns a session forgery into a clear case of remote code execution (RCE). The issue is classified under CWE-338, the use of a cryptographically weak PRNG, and carries a CVSS 4.0 score of 9.3 and a CVSS 3.1 score of 9.8 — both firmly in critical territory.

Affected versions and the race against time

HFS versions 3.0.0 through 3.2.0 are vulnerable. The vendor has addressed the problem in HFS 3.2.1. The timeline leaves little room for delay: a proof-of-concept in Python circulated in late September, lowering the barrier for opportunistic attacks, and by 1 October 2026 exploitation attempts were detected against exposed systems. The activity has been linked to an unidentified actor, underscoring that this is not a theoretical risk.

For organisations in Barcelona, Lleida, Tarragona or Girona running HFS on public IPs, the first step is to inventory every instance and determine which versions are in use. Instances in the 3.0.0–3.2.0 range should be treated as compromised until proven otherwise.

Immediate actions for administrators

  • Update to HFS 3.2.1 or later as soon as possible. If the server is exposed to the internet, treat this as an emergency change.
  • Restrict the admin interface and API to trusted networks. Segment management access so that it is never reachable from the public internet.
  • Review authentication logs for unusual login flows and for calls to sensitive endpoints such as get_config and set_config.
  • Rotate credentials if compromise is suspected. An administrator session can be used to make persistent changes, so patching alone is not enough.
  • Verify system integrity and inspect configuration files for unauthorised modifications.
  • Consider robust signing keys via COOKIE_SIGN_KEYS as a temporary containment measure, but never as a substitute for the patch.

Why perimeter hardening is not enough

This incident illustrates a pattern that repeats across Spanish SMEs and hosting providers: a single weak component, often deployed quickly and forgotten, becomes the entry point for a full breach. Under GDPR, a compromise of this nature can trigger notification obligations to the Spanish data protection authority (AEPD) if personal data is affected, with potential fines running into tens of thousands of euros. The cost of an incident — forensic analysis, downtime, legal advice and reputational damage — dwarfs the effort required to patch a file server.

Beyond patching, the real lesson is that server security must be layered. Firewalls and segmentation help, but they do not stop an attacker who already has a valid session cookie. What stops them is detecting and blocking malicious behaviour at the host level, consistently across every machine you manage.

Centralised protection with Abuse Shield

This is where Abuse Shield from ALMC.es fits naturally. Instead of configuring fail2ban separately on each server and hoping nothing slips through, Abuse Shield centralises protection across your entire fleet. It automatically blocks malicious IPs, manages fail2ban across multiple machines and shares an IP reputation feed between all your servers. When one instance detects an abusive source, the others learn about it immediately.

For system administrators, hosting companies and SMEs with their own infrastructure, this means fewer blind spots and a faster response to attacks like the one targeting HFS. Combined with timely patching and strict access controls, a shared reputation feed turns isolated servers into a coordinated defence. In a landscape where critical vulnerabilities are exploited within days, that coordination is no longer a luxury — it is a baseline requirement for anyone responsible for servers in Spain.

Related

  • How to Harden Your Servers with Fail2ban and IP Reputation Feeds
  • Fail2ban: Your First Line of Defense Against Unauthorized Server Access
  • Critical libssh2 flaw: urgent patch for SSH servers
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

API Integrations & Microservices
Backup & Disaster Recovery Plans
Process Automation Scripts and Bots
Performance Optimization
Server Management & Monitoring
Relacionados
  • Steam BrokenPipe: Local Privilege Escalation on Windows
    Cybersecurity · 3 days ago
  • Server Security in Spain: Why Fail2ban Still Matters in 2026
    Cybersecurity · 4 days ago
  • Malicious PDFs: The Silent Threat to Your Servers
    Cybersecurity · 5 days ago
  • Citrix NetScaler zero-days: detect, patch and shield your servers
    Cybersecurity · 5 days ago
  • Exposed Vite Dev Servers: How Attackers Steal Cloud Secrets
    Cybersecurity · 6 days ago
  • Citrix NetScaler Zero-Days: Why Perimeter Patching Is Not Enough
    Cybersecurity · 1 week ago
Servidores MCP Destacados
  • MCP Shrimp Task Manager
    Productivity
  • Planfix
    Productivity
  • Atlassian Bitbucket
    Version Control
  • MCP Database Server
    Database
  • Rember
    Productivity
  • TimeMCP
    Productivity
  • Drug Gene Interaction Database (DGIdb)
    Database
  • Apple Shortcuts
    Productivity
  • Java Filesystem & Web MCP Server
    File System
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-10-06
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

SaaS Suite

  • PrintFlow (print shops)
  • WebTV (digital signage)
  • VeriFactu (invoicing)
  • Time tracking

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

Shall we talk directly?

Book an appointment in my calendar — I will call you or we can meet via Google Meet

  • ✓Instant confirmation via WhatsApp
  • ✓Real-time availability
  • ✓Reminder 1 hour before
  • ✓Cancel or reschedule with a single click
Initial consultation · 30min
📅 Check availability and book