Mastodon Mastodon Mastodon Mastodon

CVE-2026-61500 vulnerability in Rejetto HFS: admin session forgery and remote code execution

Photo of author

CyberSecureFox Editorial Team

Published:

CVE-2026-61500 (CVSS 9.3) in Rejetto HTTP File Server (HFS) is being actively exploited: remote unauthenticated attackers forge administrative sessions via a predictable random number generator and gain full control over the server with the ability to perform remote code execution; all internet-facing HFS installations running versions 3.0.0–3.2.0 must be immediately updated to 3.2.1 or isolated from external access.

Technical details of the CVE-2026-61500 vulnerability

According to the official description in the GitHub Security Advisory GHSA-xxrm-3f86-v97j, the CVE-2026-61500 vulnerability is related to session forgery due to the use of a weak pseudorandom number generator in the session cookie signing mechanism:

  • affected versions: Rejetto HFS 3.0.0–3.2.0;
  • nature of the vulnerability: predictable key for signing the session cookie and forgery of an administrative session;
  • impact: obtaining full administrative access and remote code execution via the server_code configuration feature;
  • attacker type: remote unauthenticated attacker.

The problem arises because HFS uses the non-cryptographic JavaScript generator Math.random() to generate the session cookie signing key. Moreover, that same generator (the V8 engine) “exposes” its values to unauthenticated clients during the SRP login process. As researcher Alejandro Ramos points out in the public PoC CVE-2026-61500 exploit, this is enough to reconstruct the internal state of the generator:

  1. the attacker initiates several consecutive login attempts without having valid credentials;
  2. during the SRP handshake, the server returns values that depend on the same source of pseudorandomness as the cookie signing key;
  3. from a small sample of such responses, the attacker can computationally reconstruct the state of the generator;
  4. knowing the state of the generator, they reproduce the same signing key as the server and sign a “forged” administrator session cookie;
  5. the server accepts this cookie as legitimate and grants full administrative access.

The key feature of this attack vector is that it does not require intercepting legitimate traffic or compromising clients: all the information needed for the attack is provided by the server itself in response to anonymous requests. This makes the attack scalable and easy to automate.

Once administrative access is obtained, vulnerable HFS instances allow execution of arbitrary server-side JavaScript. Horizon3.ai researcher Zach Hanley notes that the HFS administrative API supports custom endpoints that execute arbitrary JavaScript code, as well as the documented server_code configuration option, which provides a direct channel for remote code execution on the server side (Horizon3.ai technical analysis).

The fix was released in July 2026 in Rejetto HFS 3.2.1, where the mechanism for generating and handling the session key was revised (HFS 3.2.1 release). However, it was only in late September 2026 that a public Python exploit appeared, drastically lowering the barrier to entry for attackers.

Active exploitation and evolution of attacks on Rejetto HFS

The timeline of events illustrates today’s typical “vulnerability discovery – PoC – mass exploitation” cycle:

  • July 2026 — patch released in HFS 3.2.1 (official release);
  • 30 September 2026 — Horizon3.ai publishes a detailed technical report, noting that the vulnerability was discovered with the assistance of the Anthropic Mythos AI model (Horizon3.ai analysis);
  • by late September 2026 — public PoC exploit by Alejandro Ramos is released (PoC repository);
  • 1 October 2026 — VulnCheck records the first real exploitation attempts against production HFS instances in the US, attributing them to an unnamed China-based attacker on the basis of network request telemetry (VulnCheck report).

This is already the second case of active exploitation of a remote vulnerability in Rejetto HFS in recent years. In 2024, the CVE-2024-23692 vulnerability (also critical, CVSS 9.8) was used by several groups to deliver cryptominers, trojans and HATVIBE malware, as detailed in the technical review by Vicarius on CVE-2024-23692.

From the perspective of MITRE ATT&CK tactics and techniques, the current attacks fall under the Exploitation of Public-Facing Application (T1190) technique: the attacker exploits a remote vulnerability in an internet-facing application to gain initial access and then deploy a payload of their choice.

Another notable aspect is the involvement of the Anthropic Mythos AI model in identifying the vulnerability. This underscores that complex cryptographic and pseudorandomness-related bugs in code will increasingly be found more quickly — by both defenders and attackers. A high degree of automation in both discovery and exploitation (available Python script plus simple HTTP requests) makes such vulnerabilities particularly attractive for large-scale campaigns.

Impact assessment for organizations

Rejetto HFS is a lightweight HTTP file server, often used for quickly serving files without complex infrastructure. This makes it popular in small companies, among contractors, and in lab and temporary environments — that is, where update and security process requirements are traditionally weaker.

If CVE-2026-61500 is successfully exploited, the attacker gains:

  • full administrative control over HFS;
  • the ability to execute arbitrary code under the HFS service account via the server_code mechanism;
  • access to files transferred through or stored on the server;
  • a potential foothold for further movement across the network (lateral movement).

Given the previously observed abuse of the CVE-2024-23692 vulnerability to install cryptominers and trojans (Vicarius analysis), it is reasonable to expect that the new vulnerability will also be used to deploy long-lived backdoors, miners and remote administration tools, often without any immediately noticeable impact on server performance.

The highest risk is borne by:

  • organizations that expose HFS directly to the internet without an intermediary proxy or VPN;
  • environments where HFS has access to internal file resources (shared network folders, backups, configuration files);
  • companies without centralized tracking of deployed software — there is a high likelihood of forgotten but still reachable HFS instances at branches, contractors and in test zones.

Failing to act on CVE-2026-61500 effectively means allowing external, unauthenticated administrative access to the file server, putting data confidentiality, infrastructure integrity and regulatory compliance at risk.

Practical recommendations for risk mitigation

1. Inventory and prioritization

  • Identify all Rejetto HFS instances in the organization, including test, temporary and contractor-hosted ones.
  • Check the HFS version in the administrative interface or from the binary; versions 3.0.0–3.2.0 should be considered vulnerable.
  • Prioritize instances that are accessible from the internet or partner networks.

2. Updates and configuration measures

  • Update all vulnerable instances to version 3.2.1 or later from the official developer repository: Rejetto HFS 3.2.1.
  • If updating is not possible in the short term:
    • restrict access to HFS by IP address (firewall, VPN, proxy filtering);
    • block external access to the administrative interface, allowing it only from a protected segment;
    • consider temporarily stopping HFS or replacing it with an alternative solution.

3. Detecting possible compromise

Since exploitation of the vulnerability does not require valid credentials and can occur very quickly, it is prudent to assume that some servers may have been compromised before the patch was installed. It is recommended to:

  • analyze HFS logs (and web server logs if it is used as a frontend) for:
    • frequent consecutive login attempts from the same external IP addresses;
    • unexpected creation or modification of administrative sessions;
    • Suspicious requests to administrative APIs and changes to settings related to server_code.
  • check the system for:
    • new or modified JavaScript files and HFS configurations;
    • unscheduled services and tasks started under the account used by HFS;
    • signs of cryptominer or remote agent installation (abnormal CPU load, unknown outbound connections).

If there are signs of compromise, you should assume the attacker has full control over the server: perform forensics, reinstall the system from a trusted source, change credentials used on this host, and check adjacent hosts for signs of lateral movement.

The critical step right now is to recheck all Rejetto HFS instances in the coming days, immediately update them to version 3.2.1 or higher or isolate them from external networks; postponing this decision in light of already observed exploitation practically guarantees successful attacks against unprotected servers.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.