Touchpoint Security Advisory

Rejetto HFS Flaw Actively Exploited, Microsoft Rushes an Exchange Fix, and Three South Korean Banks Breached

TSTouchpoint Security·October 5, 2026, 5:20 PM ET

Four developments our morning brief didn't cover: attackers are going after a critical Rejetto HFS flaw, Microsoft shipped an out-of-band Exchange fix that on-premises customers must install, Dell patched a critical remote-code-execution bug in a widely used server update tool, and three of South Korea's largest banks are investigating customer data leaks.

Priority at a glance

Only Rejetto HFS is under confirmed active exploitation right now. The Exchange and Dell flaws are not yet reported exploited but are severe enough to patch on an emergency timeline. The South Korea story is a set of access-pattern breaches at major banks, not a single software bug.

Issue Exploited Fix status Our recommended timing
Rejetto HFS, CVE-2026-61500 (forged admin session → RCE) Yes, since Oct 2 (honeypot scans) 3.2.1+ (current 3.3.4), available since Jul 13 Today, if HFS is internet-facing
On-prem Exchange, CVE-2026-96940 (cross-mailbox read) Not yet reported; Microsoft rates "more likely" Out-of-band update available now Today, on every on-prem server
Dell System Update, CVE-2026-86360 (unauthenticated root RCE) No known exploitation DSU 2.3.0.0 or later This week, on every PowerEdge running DSU
Shinhan, KB Kookmin and Hana bank data leaks (South Korea) N/A — under active FSC investigation Root cause not yet confirmed publicly Ongoing — review your own exposed systems

1. Rejetto HFS flaw now being targeted (CVE-2026-61500)

What happened. Attackers are probing and attempting to exploit CVE-2026-61500 in Rejetto HTTP File Server (HFS). VulnCheck's honeypots recorded attempts from October 2, coming from a single China Telecom IP address against decoy servers in Japan and the US. Activity followed Horizon3.ai's September 30 technical write-up and proof of concept.

Who is affected. HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from a non-cryptographic random number generator and leaks outputs of that same generator to unauthenticated users at login. An attacker can rebuild the key, forge an administrator session, and reach remote code execution. Older HFS versions have been heavily abused by attackers in the past.

Severity. SecurityWeek reports a CVSS score of 9.3. The fix has been available since July 13, in 3.2.1 (current release is 3.3.4) — this is a case of exploitation starting months after a patch existed, not a zero-day.

What to do. — click a step to check it off, click any code snippet to copy it

  1. Upgrade to HFS 3.2.1 or later (current release: 3.3.4).
  2. Take HFS off the internet if it doesn't need to be there, and invalidate existing admin sessions after upgrading.
  3. Check exposed servers for unexpected admin logins, new files or new processes since late September.

2. Microsoft Exchange: out-of-band fix for mailbox-access flaw (CVE-2026-96940)

What happened. Microsoft released out-of-band updates for CVE-2026-96940, a CVSS 8.8 privilege-escalation flaw that lets an authenticated attacker read other users' mailboxes in the same organization. Microsoft rates exploitation as "more likely." No in-the-wild exploitation has been reported yet.

Who is affected. On-premises Exchange Server Subscription Edition RTM, Exchange 2019 CU14 and CU15, and Exchange 2016 CU23. Exchange Online has already been fixed on the service side and needs no customer action.

Why it matters. Any phished user account becomes a path into executives' mail until the patch is applied — this isn't a flaw that needs a sophisticated exploit chain, just one compromised mailbox and this privilege-escalation bug.

What to do. — click a step to check it off

  1. Install the out-of-band update on every on-premises Exchange server now, don't wait for the next patch cycle.
  2. Confirm Exchange Online tenants need no action, but don't skip hybrid on-prem servers in a mixed environment.

3. Dell System Update: critical remote code execution as root (CVE-2026-86360)

What happened. Dell advisory DSA-2026-324 fixes five vulnerabilities in Dell System Update (DSU), the command-line tool used to deploy firmware and driver updates on PowerEdge servers. The most severe, CVE-2026-86360 (CVSS 9.6), is a path traversal flaw that lets an unauthenticated remote attacker run code with root privileges. The other four (CVSS 7.3–8.2) allow local privilege escalation or code execution. Dell has not reported exploitation.

Why it matters. Root-level remote code execution with no authentication required is about as severe as a vulnerability gets. DSU typically runs with elevated privileges by design, which is exactly what makes a flaw in it so consequential.

What to do. — click a step to check it off

  1. Upgrade DSU to 2.3.0.0 or later on every server where it's installed.
  2. Limit network access to systems that run DSU until the upgrade is complete.

4. South Korea: data leaks at Shinhan, KB Kookmin and Hana banks

What happened. South Korea's Financial Services Commission held an emergency meeting and opened on-site investigations after breaches at major banks. Reported impact: about 25,000 Shinhan Bank customer records and about 119,000 KB Kookmin card records, plus a more limited breach at Hana Bank through a sales-support system.

3 of South Korea's largest banks reporting customer data leaks within the same investigation window, prompting an emergency regulator meeting.

Why it matters. Multiple top-tier banks breached in quick succession points to a shared weakness in internet-facing systems rather than one isolated failure. Regulators have told financial firms to inspect all externally accessible IT systems. Local media have linked the attacks to AI-assisted tooling, but authorities have not confirmed this.

What to do. — click a step to check it off

  1. Financial institutions elsewhere should review their own internet-facing applications now, regardless of jurisdiction.
  2. Watch for the FSC's and affected banks' follow-up disclosures to see if a common root cause emerges across all three.

Also on the radar

Healthcare breaches (US) Clover Health (about 138,700 people, social engineering of employee accounts) and AngMar Management Services in Texas (about 126,200 people, claimed by the Interlock ransomware group) reported breaches to HHS. Both date from July.
Healthcare cybersecurity bill The Senate passed the bipartisan Health Care Cybersecurity and Resiliency Act (S.3315) by unanimous consent. It funds grants, supports rural providers and improves HHS–CISA coordination. It now goes to the House.
IQVIA fined €7 million Italy's data protection authority fined IQVIA for failing to properly anonymize the health data of about one million patients.
Cling botnet update New research shows the Cling Linux botnet exploiting Realtek Jungle SDK flaws and using the STUN protocol for command and control. Patch or replace exposed IoT and router devices built on that SDK.

Touchpoint's Take

The Rejetto HFS story is a reminder that "exploited" and "zero-day" aren't the same thing — this flaw had a fix available since July, and attackers only started working it in October. A patch sitting unapplied for months is still an open door, whether or not anyone's walked through it yet.

The Exchange and Dell flaws share a pattern worth watching: both are rated as not-yet-exploited but severe enough that vendors shipped fixes outside their normal release cycle. An out-of-band patch is itself a signal — vendors don't interrupt their own schedule for issues they consider low-urgency.

What we would change in a security program:

  1. Track patches you've deferred, not just patches you've applied. Rejetto HFS went unexploited for months after a fix existed, then became a live target — a deferred-patch list catches exactly this gap.
  2. Treat an out-of-band vendor patch as a priority signal on its own. Microsoft and Dell both broke from their normal release cadence here; that's worth acting on even before exploitation is confirmed.
  3. Review internet-facing financial and customer-data systems proactively. Three banks breached in the same window, in the same country, is a pattern other financial institutions should read as a warning, not just news.

If you would like help assessing your exposure to any of these issues, the Touchpoint Security team is available to talk.

Sources

  • Rejetto HFS v3.2.1 release notes (official GitHub)
  • Horizon3.ai: Rejetto HFS RCE disclosure
  • BleepingComputer: Rejetto HFS servers now actively scanned for critical RCE flaw
  • SecurityWeek: Exploitation hits Rejetto HFS vulnerability discovered by AI
  • Microsoft Security Update Guide: CVE-2026-96940
  • The Hacker News: Microsoft Exchange flaw lets authenticated attackers read other users' mailboxes
  • Dell DSA-2026-324: Security update for Dell System Update
  • BleepingComputer: New Dell System Update flaw lets hackers gain root privileges
  • BleepingComputer: South Korea probes bank breaches amid suspected AI-powered attacks
  • SecurityWeek: 250,000 impacted by data breaches at New Jersey, Texas healthcare firms
  • US Senate HELP Committee: Senate passes Chairman Cassidy's legislation to strengthen cybersecurity
  • Congress.gov: S.3315, Health Care Cybersecurity and Resiliency Act of 2026
  • BleepingComputer: IQVIA fined $7.8 million for failing to properly anonymize health data
  • The Hacker News: Realtek Jungle SDK exploit attempts deliver Cling botnet with STUN-based C2

Not sure where you stand on any of this?

Our team is available to talk through your exposure to today's issues.

Contact us