CVE-2014-7226: Rejetto HTTP File Server

High severity, CVSS 7.5. EPSS: 9.2% chance of exploitation in the next 30 days.

The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols.

Affected products

  • Rejetto HTTP File Server: up to and including 2.3c

Published 2014-10-10. Last modified 2026-06-17.