Attackers exploit Rejetto HFS flaw that lets them forge admin sessions

CVE-2026-61500 lets an unauthenticated attacker predict HFS session signing keys and take over the admin account. Exploitation was seen on October 1.

Attackers exploit Rejetto HFS flaw that lets them forge admin sessions

At a glance

  • CVE-2026-61500 carries a CVSS 9.3 rating and affects Rejetto HFS versions 3.0.0 through 3.2.0
  • HFS derives session-cookie signing keys from Math.random(), which an attacker can predict from login responses
  • A forged admin cookie gives full control and code execution through the server_code configuration feature
  • Version 3.2.1, released in July 2026, fixes the flaw; a public proof-of-concept exploit is already circulating

A critical vulnerability in Rejetto HTTP File Server (HFS), a widely used lightweight file sharing server, is being exploited in the wild after a public write-up and a working exploit appeared in late September. The Hacker News reported that VulnCheck's Patrick Garrity detected exploitation attempts on October 1, 2026, carried out by an unnamed threat actor in China against real vulnerable hosts in the United States.

The flaw is tracked as CVE-2026-61500. According to the GitHub Advisory Database entry, it is rated 9.3 on the CVSS v4 scale and affects HFS versions 3.0.0 through 3.2.0. The advisory classifies it as CWE-338, use of a cryptographically weak pseudo-random number generator, and notes the attack requires no privileges and no user interaction.

Technical details

The advisory explains that HFS derives the signing key for its session cookies from JavaScript's Math.random() function, which is not designed for cryptographic use. The same generator also produces values that the server discloses to unauthenticated clients during login attempts. An attacker who collects enough of those login responses can reconstruct the generator's internal state, recover the signing key and then sign their own session cookie.

That cookie can be issued for the administrator account, giving the attacker full administrative access without ever knowing a password. From there, the GitHub advisory states, the server_code configuration feature can be used to execute arbitrary JavaScript on the host, turning a session forgery into remote code execution on the machine running the server.

Who is affected

Any internet-reachable HFS instance on a release between 3.0.0 and 3.2.0 should be considered at risk. HFS is commonly run by small businesses, home users and project teams that need a quick way to publish files, which means many deployments sit outside formal patch management and may have been online unpatched since the summer.

The Hacker News reported that Horizon3.ai researcher Zach Hanley published the technical details of the flaw on September 30, 2026, and that security researcher Alejandro Ramos released a Python-based proof-of-concept exploit in late September. Exploitation followed within roughly a day of the write-up. The publication also noted that this is the second Rejetto HFS vulnerability to be exploited in attacks, after CVE-2024-23692 was used to deliver cryptocurrency miners and trojans.

What to do

The fix shipped some time before the attacks began: The Hacker News reported that version 3.2.1 was released in July 2026, so the practical task is identifying installations that were never updated. Administrators should upgrade to 3.2.1 or later, and treat any instance that was exposed on an older build as potentially compromised rather than simply patched.

Because the attack produces a valid administrator session, defenders should review HFS configuration for unexpected server_code entries, unfamiliar accounts or changed share paths, and check the host for processes and scheduled tasks created around the exposure window. Where an HFS instance does not need to be reachable from the internet, restricting it to a VPN or internal network removes the exposure entirely.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.