NEWS

Rejetto HFS Servers Now Actively Scanned for Critical RCE Flaw

Attackers are actively scanning for CVE-2026-61500, a weak signing-key flaw in Rejetto HFS enabling session forgery and remote code execution.

Dylan H.

News Desk

October 6, 2026
7 min read
Rejetto HFS Servers Now Actively Scanned for Critical RCE Flaw

Scanning Activity Detected Against Weak Signing Key Flaw

Threat actors have begun actively scanning for servers running Rejetto HFS (HTTP File Server), a free and open-source file-sharing tool for Windows, Linux, and macOS, that are vulnerable to CVE-2026-61500 — a critical session-forgery flaw that chains into full remote code execution (RCE). The vulnerability carries a CVSS 3.1 score of 9.8 and a CVSS 4.0 score of 9.3, and was first published to the NVD on July 13, 2026, with a patch available since that same month in version 3.2.1.

The flaw resurfaced in the headlines after security firm Horizon3 published a detailed technical write-up and proof-of-concept (PoC) exploit on September 30, 2026. Within roughly 24 hours, threat-intelligence firm VulnCheck detected probes against the vulnerability hitting its Canary Intelligence honeypot network, confirming the PoC release had triggered real-world reconnaissance activity.


Incident Details

AttributeValue
CVE IDCVE-2026-61500
Affected ProductRejetto HFS (HTTP File Server) 3.x
Affected Versions3.0.0 through 3.2.0
Fixed Version3.2.1 (latest stable: 3.3.4)
CVSS 3.1 / 4.09.8 / 9.3 (Critical)
Vulnerability ClassUse of cryptographically weak PRNG → session forgery → RCE
Discovered ByHorizon3 researcher Zach Hanley, assisted by Anthropic's Mythos model
Disclosure DateJuly 13, 2026 (patch released same month)
PoC PublishedSeptember 30, 2026
Active Scanning ObservedWithin ~24 hours of PoC publication
Scanning SourceSingle China Telecom IP address (per VulnCheck)
Targets ObservedHoneypot servers in Japan and the United States

How It Worked

A Predictable Signing Key

Rejetto HFS 3.x runs on Node.js and uses the Koa web framework, which signs session cookies using the keygrip library. According to the NVD description, when no explicit signing key is configured — which Horizon3 says is the default setup — HFS builds that signing key at startup from three consecutive outputs of Math.random(), a non-cryptographic pseudo-random number generator never intended for security-sensitive operations.

An RNG Leak That Completed the Chain

On its own, a weak PRNG-derived key is a latent risk. HFS compounded the problem by disclosing raw Math.random() outputs to unauthenticated clients during login, through an unrelated code path. Horizon3 described how its AI-assisted analysis caught the significance immediately: Mythos "didn't just flag the insecure PRNG in isolation — it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible."

From Leaked Values to Admin Session

Armed with a handful of login responses, an attacker can reconstruct the generator's internal state using a formal-methods SMT solver — researchers used Microsoft's open-source Z3 solver — to recover the session-cookie signing key. Critically, exploitation requires only a valid login-enabled username, not a password; the built-in default admin account is sufficient. With the signing key recovered, an attacker forges a valid administrator session cookie and gains full administrative access to the file server.

Admin Access to Code Execution

Rejetto HFS ships a built-in server_code configuration feature that lets administrators run custom server-side JavaScript. Once an attacker holds a forged admin session, this feature becomes a direct path to arbitrary remote code execution on the host — turning a cookie-signing weakness into complete server compromise.

Scanning in the Wild

VulnCheck VP of Security Research Caitlin Condon reported that the company's honeypot network observed probes targeting CVE-2026-61500 originating from a single China Telecom IP address, hitting decoy deployments in Japan and the United States. VulnCheck characterized the activity as small-scale reconnaissance and has not yet confirmed successful exploitation or post-exploitation behavior in the wild — but the timing, landing within a day of the Horizon3 PoC, shows how quickly published technical detail converts into scanning traffic.


Impact Assessment

Impact AreaDescription
Authentication BypassAttackers forge valid admin session cookies without needing a password
Remote Code ExecutionAdmin access enables arbitrary JavaScript execution via server_code, leading to full RCE
Data ExposureAdmin-level access permits theft, tampering, or deletion of all hosted files
Lateral MovementA compromised HFS host can serve as a foothold into the broader internal network
Malware DeploymentRCE allows attackers to drop additional payloads, including ransomware or backdoors
Low Exploitation BarrierPublic PoC and a documented solver-based technique lower the skill required to exploit

Recommendations

For System Administrators

  • Upgrade immediately to Rejetto HFS 3.2.1 or later — the current stable release is 3.3.4. This is the only complete fix, since it replaces the Math.random()-derived key with 32 bytes from Node.js's cryptographically secure randomBytes() and swaps the exposed numeric login identifier for a randomUUID().
  • If immediate upgrading is not possible, configure an explicit, strong COOKIE_SIGN_KEYS value. This mitigates signing-key prediction but is a stopgap, not a substitute for patching.
  • Audit internet-facing HFS instances now; Rejetto HFS is commonly deployed for quick, self-hosted file sharing and may have been exposed without ongoing maintenance oversight.

For Security Teams

  • Treat any internet-reachable HFS 3.0.0–3.2.0 instance as compromised-until-proven-otherwise if logs show anomalous login activity or unexpected admin-session creation.
  • Monitor for scanning indicators: repeated login attempts against HFS endpoints, especially bursts of requests consistent with harvesting Math.random() outputs from login responses.
  • Review server_code configuration history and any recently modified server-side scripts on HFS hosts for signs of post-exploitation activity.
  • Add detection rules for known scanning infrastructure where threat intelligence (e.g., VulnCheck Canary Intelligence) publishes indicators.

For Users and Operators

  • Do not expose Rejetto HFS admin interfaces directly to the internet; restrict access via VPN or IP allowlisting where file sharing must remain internet-facing.
  • Disable or restrict the server_code feature if it is not actively required for your deployment.
  • Rotate any credentials associated with HFS instances after patching, in case sessions were already forged prior to remediation.

Key Takeaways

  1. CVE-2026-61500 (CVSS 9.8) lets attackers forge administrator session cookies in Rejetto HFS 3.0.0 through 3.2.0 by exploiting a weak Math.random()-derived signing key combined with an RNG value leak during login.
  2. The forged admin session chains directly into remote code execution through HFS's built-in server_code feature — no password is required, only a valid login-enabled username.
  3. The flaw was originally discovered and patched in July 2026, but renewed attention followed Horizon3's September 30, 2026 technical write-up and PoC release, which used Anthropic's Mythos AI model to identify the exploit chain.
  4. VulnCheck detected active scanning against the vulnerability within about 24 hours of the PoC's publication, via honeypot probes from a single China Telecom IP address targeting Japan and the United States.
  5. No confirmed successful in-the-wild exploitation has been publicly reported yet, but scanning activity typically precedes broader exploitation — the window to patch is now.
  6. The only complete remediation is upgrading to Rejetto HFS 3.2.1 or later (currently 3.3.4); setting an explicit COOKIE_SIGN_KEYS value is a partial mitigation only.

Sources