Hackers Scan Rejetto HFS for CVE-2026-61500 Session Forgery and RCE Flaw
Hackers are actively scanning Rejetto HFS for CVE-2026-61500, a weak session-signing key vulnerability that can enable session forgery, account takeover, and remote code execution (RCE).
Caitlin Condon, Vice President of Security Research at VulnCheck, said the company’s Canary Intelligence honeypot observed probes targeting CVE-2026-61500 last weekend. The activity appeared to be small-scale reconnaissance from a single China Telecom IP address targeting deployments in Japan and the United States.
What is Rejetto HFS?
Rejetto HFS, also known as HTTP File Server, is a free, open-source file-sharing server for self-hosted file sharing on Windows, Linux, and macOS.
CVE-2026-61500 was first published by NIST on July 13, 2026. The session-cookie signing vulnerability affects Rejetto HFS versions 3.0.0 through 3.2.0 and was fixed in version 3.2.1.
How CVE-2026-61500 enables account takeover
The NIST vulnerability description states:
“Rejetto HFS 3.0.0 through 3.2.0 obtains session cookie signing keys from an unencrypted Math.random() generator and exposes the output of the same generator to unauthenticated clients while logged in.”
A remote attacker could collect a small number of login responses, reconstruct the generator state, recover the signing key, and forge a valid administrator session cookie. This could provide full administrative access and enable remote code execution through the server_code configuration feature.
Researchers publish proof-of-concept exploit
Horizon3 researchers discovered the vulnerability using Anthropic’s Mythos model. Their analysis identified both the weak signing-key generation and a separate leak that enabled key recovery.
Horizon3 published technical details and a proof-of-concept (PoC) exploit in a September 30, 2026, article.
“Mythos didn’t just flag the insecure PRNG in isolation; it also identified that the application had leaked the raw Math.random() output through another code path, recognized these two facts as a chain, and determined that the leak produced exactly the observations needed to make state recovery feasible,” Horizon3 said.

Source: Horizon3
Potential impact of a compromised HFS server
The researchers’ exploit chains the vulnerability with HFS’s built-in functionality to execute custom server-side JavaScript, resulting in remote code execution.
The publication of these technical details may have contributed to investigative activity targeting CVE-2026-61500. Potential attack scenarios include accessing, stealing, or deleting HFS files; installing malware on affected servers; or using a compromised host to access internal systems.
VulnCheck has not published details about exploit success or post-exploitation activity.
Rejetto HFS users should upgrade immediately
Users of Rejetto HFS should upgrade to version 3.2.1 or, preferably, the latest stable release, version 3.3.4, as soon as possible.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



