HomeSecurityRejetto HFS: Critical vulnerability under active exploitation

Rejetto HFS: Critical vulnerability under active exploitation

Rejetto HFS (HTTP File Server) is at the center of a new cyberthreat, as a critical vulnerability that allows administrative session spoofing and remote code execution (RCE) is being actively exploited by malicious actors. According to The Hacker News, cybersecurity firm VulnCheck has detected active exploit attempts targeting exposed systems in the US and Japan. The vulnerability affects versions 3.0.0 to 3.2.0 of the software, and a patch has already been released.

Rejetto HFS critical vulnerability CVE-2026-61500 session forgery RCE

The vulnerability is coded CVE-2026-61500 and is rated CVSS 9.3 (Critical) according to the CVSS 4.0 system, while in some reports based on CVSS 3.1 it reaches 9.8. This is a session forgery that results from the use of a weak pseudo-random number generator (specifically the non-cryptographic Math.random() generator). The result is a predictable session-cookie signing key, which an attacker can retrieve without any authentication.

Rejetto HFS is a lightweight HTTP File Server, widely used by small businesses, individuals, educational institutions, and IT teams to publish files via a web interface. Its simplicity of deployment often leads to direct exposure to the internet, which makes such vulnerabilities particularly dangerous.

See also: CVE-2026-65660: Critical SharePoint vulnerability actively exploited

How the CVE-2026-61500 vulnerability works in Rejetto HFS

Technical analysis of the vulnerability reveals a two-stage attack chain. In the first stage, the attacker connects to an exposed Rejetto HFS and interacts with the connection endpoints. During the SRP login handshake, the server reveals to unauthenticated users values ​​generated by the same Math.random() generator used to generate the signing key of Koa session cookies. Because the generator is not cryptographically secure, collecting a small number of responses is sufficient to reconstruct the internal state of the V8 PRNG.

In the second stage, the attacker retrieves the signing key, forges a valid administrator session cookie without knowing the password, and gains full administrative access . Through the server_code function or HFS custom endpoints , he can execute arbitrary JavaScript code on the server — and depending on execution permissions, commands on the underlying operating system. The attack requires neither authentication nor user interaction, which makes it extremely dangerous.

Rejetto HFS - SecNews.gr

The vulnerability was discovered by researcher Zach Hanley of Horizon3.ai using Anthropic 's Mythos automated vulnerability detection system . The publication of technical details comes just a day after active exploitation attempts were detected — a prime example of how quickly attackers can leverage public disclosures.

Active exploitation of Rejetto HFS and community response

VulnCheck researcher Patrick Garrity confirmed that exploit attempts were detected on October 1 , 2026 , one day after Horizon3.ai published the technical details . The company identified an anonymous threat actor, with infrastructure in China , targeting genuinely vulnerable systems in the US. In addition, attempts were reported to be linked to two US-based proxy IP addresses, suggesting the use of intermediate infrastructure to hide the true origin of the attacks.

See also: Meshtastic: Critical GitHub Actions flaw with pull_request_target allows supply chain compromise (CVE-2026-44359)

A Python- based proof-of-concept (PoC) exploit was published in late September 2026 by security researcher Alejandro Ramos (known as aramosf ). HFS Ramos generated the Koa session-cookie signing key with Math.random() and exposed outputs from the same V8 PRNG to the unauthenticated SRP login handshake. An attacker can reconstruct the state of the PRNG, recover the signing key, forge an administrative session, and use the server_code to execute JavaScript on the server described the mechanism precisely: " function ."

It is worth noting that CVE-2026-61500 is the second critical vulnerability in Rejetto HTTP File Server that is being actively exploited. In July 2024, multiple threat actors had exploited CVE-2024-23692 (CVSS: 9.8) to distribute cryptocurrency miners, trojans , and the HATVIBE malware. The pattern repeats itself: file transfer servers, exposed to the internet, are a constant target of attacks.

miniOrange SAML plugin vulnerabilities WordPress authentication bypass

Protection from the Rejetto HFS vulnerability: Immediate actions

Patch 3.2.1 was released in July 2026 and is the primary solution. Organizations and users running versions 3.0.0 through 3.2.0 should upgrade immediately. Additionally, it is recommended to remove vulnerable versions from online exposure until the upgrade is complete, and to cancel existing sessions and rotate associated secrets after the upgrade — especially if the server was accessible from the internet during the vulnerable period.

See also: Target: Dev server offline – Hackers say they stole source code

Additionally, it is recommended to restrict administrative interfaces via VPNs, IP allowlists, firewalls, or identity-aware proxies. Examining logs for unusual login responses, repeated authentication requests, unexpected administrative activity, and configuration changes is critical. Checking for post exploitation — new accounts, scheduled tasks, persistence mechanisms, cryptocurrency miners, reverse shells , or unauthorized file changes — is also essential.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS