Rejetto HFS session forgery flaw probed in the wild (CVE-2026-61500)

At a glance

Severity CRITICAL
CVSS CVE-2026-61500: 9.3
EPSS (30-day exploit probability) CVE-2026-61500: 1.0%
In CISA KEV (exploited) No
CVE IDs CVE-2026-61500

The Rejetto HFS vulnerability CVE-2026-61500 lets an unauthenticated remote attacker forge an administrator session cookie on HFS 3.0.0 through 3.2.0 and then run code on the server. VulnCheck honeypots have recorded probing for the flaw, so internet-facing HFS servers should be upgraded to 3.2.1 or later now. It is rated CVSS 9.3 (critical).

Reports differ on how far attacks have gone. BleepingComputer describes small-scale scanning, while Security Affairs says the flaw is being exploited. VulnCheck has not shared details of any successful compromise.

What happened

Rejetto HFS (HTTP File Server) is a free, open-source tool for self-hosted file sharing on Windows, Linux and macOS. The NVD entry for CVE-2026-61500 was published on July 13, 2026 through the VulnCheck CNA, and the fix shipped in HFS 3.2.1.

The problem is in how HFS protects its login sessions. It builds the key that signs session cookies from JavaScript’s Math.random(), which is not a cryptographic random number generator. During login, HFS also hands unauthenticated clients outputs from the same generator.

An attacker can collect a small number of login responses, reconstruct the generator’s internal state, recover the signing key and sign a valid administrator cookie. From there, the HFS server_code configuration feature allows custom server-side JavaScript, which gives remote code execution.

Horizon3 researcher Zach Hanley discovered the flaw. Horizon3 says it found it using Anthropic’s Mythos model under Project Glasswing, which linked the weak key generation to the output leak. Horizon3 published a write-up with a proof-of-concept exploit on September 30, 2026.

Am I affected? Rejetto HFS versions at risk

  • Affected: Rejetto HFS 3.0.0 through 3.2.0.
  • Fixed: 3.2.1. BleepingComputer reports the latest stable release is 3.3.4 and recommends that.
  • Older 2.x releases are not named as affected in the sources we reviewed. The Delphi 2.x line was replaced by the TypeScript-based 3.x branch.
  • The NVD record lists no structured affected-product data, so confirm your version in the HFS admin interface or from the install files.

Technical details

  • Weakness: CWE-338, use of a cryptographically weak pseudo-random number generator.
  • Vector: network, low complexity, no privileges and no user interaction (CVSS 4.0 base score 9.3).
  • Impact: high confidentiality, integrity and availability impact on the vulnerable server.
  • Exploitation status: VulnCheck’s Canary Intelligence honeypots observed probes. BleepingComputer, citing VulnCheck, says the activity looked like reconnaissance from a single China Telecom IP address against deployments in Japan and the United States.
  • CISA KEV: no KEV entry for CVE-2026-61500 was found in the data we checked. HFS has been in KEV before, for CVE-2024-23692, an unauthenticated template injection leading to RCE.
  • EPSS: 0.00987, a low score that does not yet reflect the new probing.

Why this matters

Analysis, not new facts. Public proof-of-concept code, a low-complexity network attack and no authentication required usually shorten the time between disclosure and widespread scanning. The probing began days after the Horizon3 write-up, which fits that pattern.

HFS is often run by individuals and small teams on ad hoc servers, sometimes exposed to the internet and outside patch management. Those are the instances most likely to be missed. A compromised file server can also serve as a foothold into the internal network.

The scanning reported so far is low volume, but treat it as the start of a pattern, not the full extent of it. If an exposed HFS 3.x server cannot be patched today, take it off the internet.

What to do: fix CVE-2026-61500

  1. Inventory every HFS instance, including ones on workstations, lab machines and cloud VMs. Check the version.
  2. Upgrade any 3.0.0 to 3.2.0 instance to 3.2.1 at minimum, and preferably to the latest stable release (3.3.4 per BleepingComputer).
  3. Until patched, restrict access to trusted networks or a VPN, or stop the service. No other workaround is described in the sources.
  4. Rotate the HFS admin credentials after upgrading and review the admin accounts and configuration.
  5. Hunt for compromise, as described below, on any server that was exposed while running an affected version.

Detection and hunting ideas

The sources give no indicators of compromise beyond the single scanning source’s network and country. Detection ideas that follow from the attack chain:

  • Look for bursts of repeated login requests to HFS from one address, since the attack needs several login responses to recover the key.
  • Check for new or changed server_code content in the HFS configuration, which is the code execution path described.
  • Review the HFS process for unexpected child processes, outbound connections or new files, and check admin sessions that do not match a known login.
  • Search web and reverse-proxy logs for the timeframe since September 30, 2026, when the proof-of-concept became public.

Possible consequences described by BleepingComputer include theft or deletion of hosted files, malware installation and use of the host to reach internal systems. VulnCheck has not reported any post-exploitation activity.

What is not yet known

  • Whether any servers have been compromised through this flaw is not disclosed.
  • No threat actor has been named, and attribution is not established.
  • The number of exposed HFS 3.x servers is not disclosed in the sources.

Sources