Rejetto HFS CVE-2026-61500 faces exploitation attempts after a public PoC showed forged admin sessions can lead to remote code execution.