Rejetto HFS session-forgery flaw (CVE-2026-61500) under attack
Attackers are forging admin sessions on Rejetto HFS via CVE-2026-61500, a weak-PRNG flaw scored 9.3. Fix is in 3.2.1; VulnCheck reports exploitation and a PoC is public.
Attackers are forging administrator sessions against internet-facing Rejetto HTTP File Server instances. CVE-2026-61500 (CVSS 9.3) lets an unauthenticated attacker recover the key HFS uses to sign session cookies, mint a valid admin cookie, and reach remote code execution through the server's server_code configuration feature. VulnCheck reported exploitation attempts beginning the first week of October, and a working proof-of-concept is already public.
What the bug does
HFS signs session cookies with a value drawn from Math.random() — the non-cryptographic xorshift128+ generator in its Node.js runtime. The server discloses enough generator output to unauthenticated clients during login that an attacker can collect a handful of responses, reconstruct the generator's internal state, and recover the signing key. From there, forging an administrator session cookie is deterministic, and HFS's server_code feature turns admin access into code execution on the host.
The flaw was reported by Horizon3.ai researcher Zach Hanley on September 30. Horizon3 says the bug was surfaced with AI assistance — their tooling recognized that the Math.random() outputs were reversible. Treat the "found by AI" framing as a sourcing note, not the story: the root cause is an old one, a predictable PRNG guarding an authentication secret.
Affected versions
Per the advisory, every HFS build before 3.2.1 on the affected branch is vulnerable. The fix shipped in 3.2.1 on July 13, 2026 — so patched instances have been available for nearly three months, but exposed unpatched servers remain.
Find your exposed instances. HFS fingerprints are indexable; a Shodan search for the default banner is a starting point:
http.title:"HFS /"
Exploitation status
VulnCheck is the source for in-the-wild activity, reporting exploitation attempts against exposed hosts in the US and Japan, originating from a China Telecom IP address. VulnCheck characterized the early activity as small-scale reconnaissance rather than mass exploitation. A Python proof-of-concept published by researcher Alejandro Ramos (aramosf) in late September lowers the bar further — expect opportunistic scanning to broaden now that the key-recovery technique is public.
Action checklist
- Upgrade to HFS 3.2.1 or later today if your instance is reachable from untrusted networks. The patch has existed since July; there is no reason to still be on a vulnerable build.
- Take HFS off the public internet where you can. It is a personal/SMB file server, not an edge appliance — put it behind a VPN or an authenticating reverse proxy.
- Hunt for forged sessions. Review admin-panel access and any use of the
server_codefeature you did not configure. Unexpected changes to HFS configuration are the clearest sign of compromise. - Assume key compromise on any exposed, unpatched box. Patching does not evict an attacker who already forged a session — rebuild or fully audit anything that was internet-facing while unpatched.
Context
This is the second critical Rejetto HFS flaw to draw active exploitation in just over a year. CVE-2024-23692 (CVSS 9.8), a template-injection RCE, was weaponized in mid-2024 to drop cryptocurrency miners and other malware on exposed servers. The pattern is consistent: a widely deployed, often internet-exposed file server with a small maintainer footprint, attacked within weeks of a public PoC. If you run HFS at the edge, the recurring lesson is to stop running it there.
Full details for CVE-2026-61500 are on NVD.