Scanning Activity Detected Against Weak Signing Key Flaw
Threat actors have begun actively scanning for servers running Rejetto HFS (HTTP File Server), a free and open-source file-sharing tool for Windows, Linux, and macOS, that are vulnerable to CVE-2026-61500 — a critical session-forgery flaw that chains into full remote code execution (RCE). The vulnerability carries a CVSS 3.1 score of 9.8 and a CVSS 4.0 score of 9.3, and was first published to the NVD on July 13, 2026, with a patch available since that same month in version 3.2.1.
The flaw resurfaced in the headlines after security firm Horizon3 published a detailed technical write-up and proof-of-concept (PoC) exploit on September 30, 2026. Within roughly 24 hours, threat-intelligence firm VulnCheck detected probes against the vulnerability hitting its Canary Intelligence honeypot network, confirming the PoC release had triggered real-world reconnaissance activity.
Incident Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-61500 |
| Affected Product | Rejetto HFS (HTTP File Server) 3.x |
| Affected Versions | 3.0.0 through 3.2.0 |
| Fixed Version | 3.2.1 (latest stable: 3.3.4) |
| CVSS 3.1 / 4.0 | 9.8 / 9.3 (Critical) |
| Vulnerability Class | Use of cryptographically weak PRNG → session forgery → RCE |
| Discovered By | Horizon3 researcher Zach Hanley, assisted by Anthropic's Mythos model |
| Disclosure Date | July 13, 2026 (patch released same month) |
| PoC Published | September 30, 2026 |
| Active Scanning Observed | Within ~24 hours of PoC publication |
| Scanning Source | Single China Telecom IP address (per VulnCheck) |
| Targets Observed | Honeypot servers in Japan and the United States |
How It Worked
A Predictable Signing Key
Rejetto HFS 3.x runs on Node.js and uses the Koa web framework, which signs session cookies using the keygrip library. According to the NVD description, when no explicit signing key is configured — which Horizon3 says is the default setup — HFS builds that signing key at startup from three consecutive outputs of Math.random(), a non-cryptographic pseudo-random number generator never intended for security-sensitive operations.
An RNG Leak That Completed the Chain
On its own, a weak PRNG-derived key is a latent risk. HFS compounded the problem by disclosing raw Math.random() outputs to unauthenticated clients during login, through an unrelated code path. Horizon3 described how its AI-assisted analysis caught the significance immediately: Mythos "didn't just flag the insecure PRNG in isolation — it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible."
From Leaked Values to Admin Session
Armed with a handful of login responses, an attacker can reconstruct the generator's internal state using a formal-methods SMT solver — researchers used Microsoft's open-source Z3 solver — to recover the session-cookie signing key. Critically, exploitation requires only a valid login-enabled username, not a password; the built-in default admin account is sufficient. With the signing key recovered, an attacker forges a valid administrator session cookie and gains full administrative access to the file server.
Admin Access to Code Execution
Rejetto HFS ships a built-in server_code configuration feature that lets administrators run custom server-side JavaScript. Once an attacker holds a forged admin session, this feature becomes a direct path to arbitrary remote code execution on the host — turning a cookie-signing weakness into complete server compromise.
Scanning in the Wild
VulnCheck VP of Security Research Caitlin Condon reported that the company's honeypot network observed probes targeting CVE-2026-61500 originating from a single China Telecom IP address, hitting decoy deployments in Japan and the United States. VulnCheck characterized the activity as small-scale reconnaissance and has not yet confirmed successful exploitation or post-exploitation behavior in the wild — but the timing, landing within a day of the Horizon3 PoC, shows how quickly published technical detail converts into scanning traffic.
Impact Assessment
| Impact Area | Description |
|---|---|
| Authentication Bypass | Attackers forge valid admin session cookies without needing a password |
| Remote Code Execution | Admin access enables arbitrary JavaScript execution via server_code, leading to full RCE |
| Data Exposure | Admin-level access permits theft, tampering, or deletion of all hosted files |
| Lateral Movement | A compromised HFS host can serve as a foothold into the broader internal network |
| Malware Deployment | RCE allows attackers to drop additional payloads, including ransomware or backdoors |
| Low Exploitation Barrier | Public PoC and a documented solver-based technique lower the skill required to exploit |
Recommendations
For System Administrators
- Upgrade immediately to Rejetto HFS 3.2.1 or later — the current stable release is 3.3.4. This is the only complete fix, since it replaces the
Math.random()-derived key with 32 bytes from Node.js's cryptographically securerandomBytes()and swaps the exposed numeric login identifier for arandomUUID(). - If immediate upgrading is not possible, configure an explicit, strong
COOKIE_SIGN_KEYSvalue. This mitigates signing-key prediction but is a stopgap, not a substitute for patching. - Audit internet-facing HFS instances now; Rejetto HFS is commonly deployed for quick, self-hosted file sharing and may have been exposed without ongoing maintenance oversight.
For Security Teams
- Treat any internet-reachable HFS 3.0.0–3.2.0 instance as compromised-until-proven-otherwise if logs show anomalous login activity or unexpected admin-session creation.
- Monitor for scanning indicators: repeated login attempts against HFS endpoints, especially bursts of requests consistent with harvesting
Math.random()outputs from login responses. - Review
server_codeconfiguration history and any recently modified server-side scripts on HFS hosts for signs of post-exploitation activity. - Add detection rules for known scanning infrastructure where threat intelligence (e.g., VulnCheck Canary Intelligence) publishes indicators.
For Users and Operators
- Do not expose Rejetto HFS admin interfaces directly to the internet; restrict access via VPN or IP allowlisting where file sharing must remain internet-facing.
- Disable or restrict the
server_codefeature if it is not actively required for your deployment. - Rotate any credentials associated with HFS instances after patching, in case sessions were already forged prior to remediation.
Key Takeaways
- CVE-2026-61500 (CVSS 9.8) lets attackers forge administrator session cookies in Rejetto HFS 3.0.0 through 3.2.0 by exploiting a weak
Math.random()-derived signing key combined with an RNG value leak during login. - The forged admin session chains directly into remote code execution through HFS's built-in
server_codefeature — no password is required, only a valid login-enabled username. - The flaw was originally discovered and patched in July 2026, but renewed attention followed Horizon3's September 30, 2026 technical write-up and PoC release, which used Anthropic's Mythos AI model to identify the exploit chain.
- VulnCheck detected active scanning against the vulnerability within about 24 hours of the PoC's publication, via honeypot probes from a single China Telecom IP address targeting Japan and the United States.
- No confirmed successful in-the-wild exploitation has been publicly reported yet, but scanning activity typically precedes broader exploitation — the window to patch is now.
- The only complete remediation is upgrading to Rejetto HFS 3.2.1 or later (currently 3.3.4); setting an explicit
COOKIE_SIGN_KEYSvalue is a partial mitigation only.