NEWS

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Hackers are exploiting CVE-2026-61500, a critical weak-PRNG flaw in Rejetto HFS that forges admin session cookies and leads to full RCE.

Dylan H.

News Desk

October 5, 2026
8 min read
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Active Exploitation of Critical Rejetto HFS Session Forgery Flaw

A critical vulnerability in Rejetto HTTP File Server (HFS) is now being actively exploited in the wild, according to threat intelligence firm VulnCheck. The flaw, tracked as CVE-2026-61500 and carrying a CVSS 4.0 score of 9.3 (CVSS 3.1: 9.8), allows an unauthenticated remote attacker to forge a valid administrator session cookie and ultimately achieve remote code execution (RCE) on the underlying server. VulnCheck, which also serves as the CVE Numbering Authority for the flaw, says it began observing exploitation attempts on October 1, 2026 — roughly one day after a detailed technical write-up and proof-of-concept video were published publicly.

The root cause is a textbook case of CWE-338, the use of a cryptographically weak pseudo-random number generator (PRNG) in a security-sensitive context. HFS versions 3.0.0 through 3.2.0 derive the signing key for Koa session cookies from JavaScript's non-cryptographic Math.random() function — and, critically, the same server also leaks raw outputs of that generator to unauthenticated clients during the login handshake. That combination lets an attacker reconstruct the PRNG's internal state, recover the signing key, and mint a fully valid administrator session cookie without ever supplying credentials.


Incident Details

AttributeValue
CVE IDCVE-2026-61500
CVSS Score9.3 (CVSS 4.0, Critical) / 9.8 (CVSS 3.1)
Weakness ClassCWE-338 — Use of Cryptographically Weak PRNG
Affected ProductRejetto HTTP File Server (HFS)
Affected Versions3.0.0 through 3.2.0
Patched Version3.2.1 and later (released July 13, 2026)
Attack VectorNetwork, unauthenticated, no user interaction
ImpactAdmin session forgery → Remote Code Execution
First Public PoCSeptember 26, 2026 (researcher Alejandro Ramos)
Detailed Write-up / VideoSeptember 30, 2026 (Horizon3.ai)
First Observed ExploitationOctober 1, 2026 (VulnCheck Canary honeypots)
Attacker InfrastructureChina-hosted IPs initially; later US-based proxy IPs
Targets ObservedServers in the United States and Japan
Discovery MethodAI-assisted research (Anthropic "Mythos" model, Horizon3.ai "Project Glasswing")
KEV StatusAdded to VulnCheck's Known Exploited Vulnerabilities catalog

How It Worked

A weak PRNG at the root of the trust chain

Rejetto HFS uses the Koa web framework's session-cookie mechanism, which requires a secret signing key to prevent cookie tampering. Instead of generating that key with a cryptographically secure random source, HFS called JavaScript's Math.random() — which, in the V8 engine that powers Node.js, is implemented with the xorshift128+ algorithm. Xorshift128+ is fast and statistically fine for non-security use, but it is deterministic and fully reversible: if an attacker observes enough raw output from the generator, the entire internal state — and therefore all future and past outputs, including the signing key — can be mathematically reconstructed.

The second half of the flaw is what made exploitation practical: HFS's unauthenticated SRP login handshake (loginSrp1) exposed numeric values drawn directly from that same PRNG to any client attempting to log in, including a loggingIn.sid value and a signed session cookie delivered in the Set-Cookie response header — with no credentials required to trigger the leak.

Reconstructing the signing key

According to the public proof-of-concept and Horizon3.ai's analysis, the exploit chain works as follows:

  1. The attacker sends a small number of unauthenticated loginSrp1 requests (as few as six) for the known built-in admin account.
  2. Each response leaks a PRNG-derived numeric value, exposing 53 of the 64 bits that make up a JavaScript floating-point double.
  3. The attacker brute-forces the remaining 11 omitted low-order bits per sample, and feeds the resulting partial-state data into the Z3 constraint solver.
  4. Z3 reverses and advances the xorshift128+ recurrence relation until it finds a single internal generator state consistent with every observed value.
  5. With the internal state recovered, the attacker derives the exact session-signing key HFS is using at that moment and forges a validly signed administrator session cookie.

From admin access to RCE

Once an attacker holds a forged admin cookie, they inherit full administrative control of the file server through its web UI. HFS ships a built-in server_code configuration feature that lets an authenticated administrator execute arbitrary JavaScript on the host — a legitimate automation feature that becomes a ready-made remote code execution primitive the moment admin access is obtained through forgery rather than a real credential.

Notably AI-assisted discovery

VulnCheck and Horizon3.ai credit the discovery of this specific flaw to AI-assisted vulnerability research. Horizon3.ai researcher Zach Hanley, working with Anthropic Research under an effort dubbed "Project Glasswing," used Anthropic's "Mythos" model to apply advanced mathematical reasoning that recognized Math.random() outputs leaked during login could be reversed to recover the session-signing key — a pattern that is easy for automated reasoning to spot but easy for human reviewers to miss in a routine code audit.

Impact Assessment

Impact AreaDescription
Authentication BypassNo credentials or user interaction needed; full admin takeover via cookie forgery
Remote Code Executionserver_code feature allows arbitrary JavaScript execution post-compromise
ConfidentialityFull read access to all files hosted and served by the compromised HFS instance
IntegrityAttacker can modify server configuration, upload/replace served files, and persist backdoors
AvailabilityServer can be reconfigured or taken offline by the attacker at will
Scope of ExposureAny internet-reachable HFS instance running versions 3.0.0–3.2.0
Detection DifficultyExploitation traffic resembles normal login activity until the forged cookie is used
Scoring GapEPSS predicted only a 0.75% chance of exploitation within 30 days — attacks began anyway, underscoring the limits of predictive scoring once public PoCs exist

Recommendations

For Rejetto HFS Administrators

  • Upgrade immediately to Rejetto HFS 3.2.1 or later, which derives the session-signing key from a secure random source and removes the PRNG-output leak from the login handshake.
  • If upgrading cannot happen immediately, take the HFS web interface offline or restrict it to a trusted internal network via firewall rules — do not expose it directly to the internet.
  • Rotate any credentials and review the server_code configuration for unauthorized entries, since a forged admin session could have already modified it.
  • Audit server logs for repeated, rapid loginSrp1 requests against the admin account, which is the signature of the key-recovery phase of this attack.

For Security Teams

  • Add CVE-2026-61500 to vulnerability scanning and asset-inventory checks; treat any internet-facing HFS instance below version 3.2.1 as compromised until proven otherwise.
  • Monitor for indicators of compromise consistent with VulnCheck's reporting: anomalous admin logins immediately preceded by bursts of unauthenticated login attempts, and outbound connections initiated from the HFS host following a login event.
  • Treat this incident as a reminder to audit other internal and legacy applications for Math.random() (or equivalent) use in session, token, or key generation — the same CWE-338 pattern is common in older or lightly maintained web software.
  • Add the CVE to threat-intel and SIEM watchlists given its presence on VulnCheck's KEV catalog and ongoing exploitation from both China-hosted and proxied US-based infrastructure.

For General Users

  • If you run a personal or small-business file share on Rejetto HFS, check your installed version now and update without delay — this software is a known recurring target (a prior unauthenticated RCE, CVE-2024-23692, was exploited in 2024 to deliver cryptocurrency miners and malware).
  • Avoid exposing file-sharing utilities like HFS directly to the public internet; use a VPN or reverse proxy with authentication in front of administrative interfaces whenever possible.

Key Takeaways

  1. CVE-2026-61500 (CVSS 9.3/9.8) lets unauthenticated attackers forge administrator session cookies in Rejetto HFS versions 3.0.0 through 3.2.0 by reversing a weak Math.random()-based PRNG.
  2. The flaw combines two mistakes: using a non-cryptographic PRNG for a security-sensitive signing key, and leaking that same generator's raw output to unauthenticated clients during login.
  3. Forged admin access escalates directly to remote code execution through HFS's built-in server_code feature.
  4. VulnCheck observed real-world exploitation beginning October 1, 2026, from China-hosted infrastructure against targets in the US and Japan, roughly one day after a public write-up and PoC video appeared — despite a patch having existed since July 13, 2026.
  5. The vulnerability was notably surfaced through AI-assisted vulnerability research (Anthropic's "Mythos" model working with Horizon3.ai's Zach Hanley under "Project Glasswing"), highlighting a growing role for AI reasoning in finding subtle cryptographic design flaws.
  6. Organizations running any version of HFS prior to 3.2.1 should upgrade immediately and treat exposed instances as a high-priority remediation item.

Sources