MikhbarMIKHBAR
Cybersecurity

Rejetto HFS Servers Scanned for Critical RCE Flaw

Security researchers have detected active scanning activity targeting a critical session forgery and remote code execution vulnerability affecting Rejetto HFS servers.

Rejetto HFS Servers Scanned for Critical RCE Flaw

Active Scans Target Rejetto HFS Flaw

Threat actors are actively scanning for a critical weak signing key vulnerability in Rejetto HFS servers, which is tracked under the identifier CVE-2026-61500. According to reports published by <a href="https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/">BleepingComputer</a>, this security flaw allows for session forgery, account takeover, and remote code execution.

Caitlin Condon, the VP of Security Research at VulnCheck, revealed over the weekend that the company's Canary Intelligence honeypots detected probes targeting CVE-2026-61500. The observed reconnaissance activity appears to be small-scale, originating from a single China Telecom IP address and probing deployments located in Japan and the United States.

Understanding the Rejetto HFS Vulnerability

Rejetto HFS (HTTP File Server) is a popular <a href="https://github.com/rejetto/hfs">open-source</a> file-sharing server tool utilized for self-hosted file sharing across Windows, Linux, and macOS platforms. The security issue itself involves a session-cookie signing weakness and leakage problem.

Tracked as CVE-2026-61500 and <a href="https://nvd.nist.gov/vuln/detail/cve-2026-61500">first published on July 13, 2026</a>, the vulnerability impacts Rejetto HFS versions 3.0.0 through 3.2.0. The application derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of this generator to unauthenticated clients during the login process.

Because of this design flaw, a remote attacker can collect a small number of login responses, reconstruct the state of the random number generator, recover the signing key, and forge a valid administrator session cookie. This grants full administrative access and allows remote code execution via the server_code configuration feature.

Recovering the session key
Recovering the session key Source: Horizon3 · Source: BleepingComputer

Discovery via AI and Technical Details

Researchers at Horizon3 discovered the underlying flaw using Anthropic's Mythos model. The model successfully identified both the weak signing-key generation and the leakage path that enabled key recovery. Detailed technical findings were <a href="https://horizon3.ai/attack-research/disclosures/anthropic-mythos-rejetto-hfs-rce/">explained Horizon3</a> in a write-up published on September 30, 2026.

According to the researchers, the AI tool recognized that the application leaked raw Math.random() outputs through a separate code path, linked those facts together, and determined that the data leak produced the exact observations required to make state recovery feasible.

The proof-of-concept exploit published by Horizon3 demonstrates the attack chain by abusing the built-in ability of HFS to execute custom server-side JavaScript, ultimately achieving remote code execution. The release of these technical write-ups and scripts likely triggered the recent wave of scanning activity targeting CVE-2026-61500.

Potential Risks and Mitigation Guidance

Potential attack scenarios involving this vulnerability include accessing, stealing, or deleting files stored on the HFS server, installing malicious software directly onto the server, or leveraging the compromised host to gain access to broader internal systems.

Despite active scanning probes being detected, VulnCheck has not shared evidence of widespread <a href="https://www.bleepingcomputer.com/news/security/hackers-attack-hfs-servers-to-drop-malware-and-monero-miners/">successful exploitation</a> or malicious post-exploitation activity in the wild at this time.

Administrators and users managing Rejetto HFS deployments are strongly encouraged to upgrade their installations immediately. The vulnerability is fully addressed in Rejetto HFS version 3.2.1, and users should ideally update to the latest stable release, version 3.3.4, to ensure complete protection against potential attacks.

Sources

Continue chronologically

You are readingRejetto HFS Servers Scanned for Critical RCE Flaw
Senate Passes Bipartisan Healthcare Cybersecurity Bill
Older storySenate Passes Bipartisan Healthcare Cybersecurity BillOctober 5, 2026 · 4 min

Related entity coverage