Critical Rejetto HFS RCE Flaw Under Active Exploitation Scans
Security researchers have detected active scanning activities targeting a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-61500, in Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0. This flaw, stemming from a weak session-cookie signing key generation and leakage issue, allows remote attackers to achieve full administrative access and execute arbitrary code on affected servers. The observed scanning activity underscores the urgency for administrators to address this vulnerability immediately.
Technical Details of the Rejetto HFS Weak Signing Key Vulnerability
CVE-2026-61500, first disclosed on July 13, 2026, impacts Rejetto HFS, a popular free and open-source file-sharing server for Windows, Linux, and macOS. According to BleepingComputer, the vulnerability lies in how HFS versions 3.0.0 through 3.2.0 generate session-cookie signing keys. Specifically, the system uses the non-cryptographic Math.random() generator, whose outputs are inadvertently disclosed to unauthenticated clients during the login process.
Horizon3 researchers discovered this flaw using Anthropic’s Mythos model. Their analysis revealed a critical chain: not only was the Pseudo-Random Number Generator (PRNG) insecure, but the application also leaked raw Math.random() outputs via a separate code path. This combination allows an attacker to collect a small number of login responses, reconstruct the generator’s state, recover the session-cookie signing key, and then forge a valid administrator session cookie. With administrative access, attackers can leverage HFS’s server_code configuration feature to execute custom server-side JavaScript, leading to remote code execution.
Possible attack scenarios following successful exploitation include unauthorized access, theft, or deletion of files, installation of malware on the server, or using the compromised host as a pivot point to access internal networks. The release of a proof-of-concept (PoC) exploit by Horizon3 on September 30, 2026, likely contributed to the recent increase in probing activity observed by VulnCheck’s Canary Intelligence honeypots. While initial observations suggest small-scale reconnaissance from a single China Telecom IP address targeting deployments in Japan and the United States, the potential for wider, more damaging attacks is significant.
Actionable Recommendations and Mitigations for CVE-2026-61500 RCE
Given the active scanning and the severity of this remote code execution flaw, organizations using Rejetto HFS must prioritize immediate action to secure their systems.
- Upgrade Immediately: The most critical step is to patch Rejetto HFS. Users are strongly recommended to upgrade to version 3.2.1, which contains the fix for this vulnerability. Ideally, administrators should update to the latest stable release, version 3.3.4, to benefit from all recent security enhancements and bug fixes. This is the primary method to mitigate CVE-2026-61500.
- Network Segmentation: Isolate HFS servers from critical internal networks where possible. This can limit lateral movement in the event of a successful compromise.
- Monitoring and Logging: Enhance monitoring for unusual activity originating from HFS servers, including unexpected outbound connections or anomalous resource utilization. Review access logs for suspicious login attempts or administrator session activity.
- Web Application Firewall (WAF): Deploy a WAF in front of HFS servers to help detect and block known exploit patterns, though patching remains the most effective defense against this specific flaw.
Failure to address this critical vulnerability could lead to significant data breaches, system compromise, and further attacks on an organization’s infrastructure. Implementing these recommendations will help safeguard against the exploitation of the Rejetto HFS 3.0.0 through 3.2.0 weak signing key vulnerability.
Related: NatJack Attacks: Exploiting NAT Trust in Windows, Linux, macOS, CVE-2026-66066: Unauthenticated File Read in Rails Active Storage