
Rejetto HFS Flaw Actively Exploited to Forge Admin Access
Attackers are targeting a patched Rejetto HFS flaw that lets them forge admin sessions and run code. Update to version 3.2.1 now.
Attackers are actively targeting a patched vulnerability in Rejetto HTTP File Server (HFS), a self-hosted file sharing application that lets people make files available over the web through a browser. Security company VulnCheck confirmed exploitation attempts on October 1, 2026, one day after Horizon3.ai published additional technical details. The flaw is tracked as CVE-2026-61500 with a CVSS severity score of 9.3, and it affects HFS versions 3.0.0 through 3.2.0. The vendor released a fix in version 3.2.1 in July 2026, but not every instance has been updated.
The vulnerability is a session forgery problem caused by a predictable key. HFS creates the secret used to sign session cookies with Math.random(), a JavaScript pseudo-random number generator (PRNG) that was never intended for cryptographic security. A PRNG that is not cryptographically secure produces numbers that can be predicted if enough outputs are observed. HFS also exposes outputs from the same generator to unauthenticated users during the login handshake. An attacker can collect a small number of login responses, reconstruct the generator's internal state, recover the signing key and forge a valid administrator session cookie. With that cookie, the attacker gains full administrative access. From the admin panel, the attacker can then use the documented server_code configuration feature to execute arbitrary JavaScript on the server, which means remote code execution.
Horizon3.ai researcher Zach Hanley described the issue as an authentication bypass that enables arbitrary remote code execution. Hanley said that the administrative part of HFS includes custom endpoints that can be set up to run JavaScript code. Combined with the ability to forge an administrator session, this meant that an attacker could move from having no authorized access to complete administrative control, and from there execute code remotely. Hanley also credited Anthropic's Mythos model for assisting in the discovery.
A patch was released in July 2026 as version 3.2.1, but many public-facing servers have not applied it. In late September, security researcher Alejandro Ramos, also known as aramosf, published a Python-based proof-of-concept (PoC) exploit. Ramos explained that HFS created the key used to sign session cookies with JavaScript Math.random() and also revealed outputs from the same generator, which is part of the V8 JavaScript engine, during the unauthenticated login process. By using those outputs, an attacker could reconstruct the PRNG state, recover the signing key, forge an administrator session and then use the server_code configuration feature to run server-side JavaScript. A proof-of-concept is a working demonstration that shows how an attack can be carried out; its public release often acts as a trigger for real-world exploitation.
VulnCheck's Patrick Garrity said exploitation attempts were detected on October 1, 2026, one day after Horizon3.ai published additional details. VulnCheck identified an unnamed threat actor in China targeting real vulnerable hosts in the U.S. Caitlin Condon, vice president of research at VulnCheck, said in a LinkedIn post that the activity so far looks like small-scale reconnaissance only. A single China Telecom IP address was probing VulnCheck Canary deployments in Japan and the United States. Reconnaissance means the attacker is currently testing for vulnerable servers rather than launching a widespread compromise.
This is not the first time Rejetto HFS has faced active exploitation. CVE-2024-23692, with a CVSS score of 9.8, was weaponized in the wild in July 2024 by multiple threat actors to deliver cryptocurrency miners, trojans and malware called HATVIBE. CVE-2026-61500 is therefore the second HFS vulnerability to attract in-the-wild attacks. The earlier incident shows how quickly attackers can turn a disclosed HFS flaw into real infections.
For website owners and IT teams, the practical takeaway is to verify every public-facing file server is running a fixed version. Because the flaw lets unauthenticated attackers work toward full administrative control, an unpatched HFS instance exposes both the files it shares and the underlying server. Even if the current exploitation is described as reconnaissance, the public release of working exploit code greatly increases the chance of broader attacks.
For teams that self-host file servers or other internet-facing infrastructure, AEU-I offers security-first IT, infrastructure and consulting that can help keep such services patched and configured safely. Applying vendor updates and restricting administrative access remain the most effective defenses.
How to Protect Yourself
- If you run Rejetto HTTP File Server, update it to version 3.2.1 or newer right away.
- Check your server's administrative settings for any user accounts or sessions you do not recognize.
- Restrict access to the server's admin page so only trusted computers on your own network can reach it.
- Look at the server's login history for sign-ins from places or times you do not expect.
- Keep a current backup of all files stored on the file server in case you need to recover from an attack.
- If you cannot update quickly, take the server offline until you can apply the fix.
Vulnerabilities & Fixes
- CVE-2024-23692 A prior critical Rejetto HFS vulnerability that was actively exploited in July 2024 to deliver cryptocurrency miners, trojans, and HATVIBE malware; users should update to a current HFS version. View the fix & details →
- CVE-2026-61500 A session forgery vulnerability in Rejetto HFS 3.0.0 through 3.2.0 that can lead to admin session forgery and remote code execution; fixed in version 3.2.1. View the fix & details →
Terms Explained
- pseudo-random number generator (PRNG) A program that produces numbers that look random but can be predicted once enough of them are observed.
- remote code execution (RCE) A type of attack that lets someone run their own commands on a computer they do not have permission to use.
- session cookie A small piece of data a website gives your browser to remember that you are logged in.
- proof-of-concept (PoC) A working demonstration that shows how a security flaw can be exploited.
- CVSS score A standard number from 0 to 10 that rates how serious a software vulnerability is.
- authentication bypass A way to get into a system without proving who you are, such as by forging a login token.