Critical Rejetto HFS Vulnerability Under Active Attack: Admin Forgery & RCE

A major security flaw in Rejetto HTTP File Server (HFS) is being actively exploited, enabling attackers to forge admin sessions and execute remote code. The vulnerability, tracked as CVE-2026-61500 and rated 9.3 in severity, arises from a weak pseudo-random number generator (PRNG) that undermines session cookie signing. Affected versions range from 3.0.0 through 3.2.0.

What’s Going Wrong & How Attackers Take Over

HFS uses JavaScript’s non-crypto Math.random() utility to derive the signing key for session cookies. Outputs of the same generator are exposed to unauthenticated clients during the login handshake, allowing an attacker to collect a few responses, reconstruct the PRNG’s internal state, recover the signing key, and forge a valid administrator session cookie. Once forged, full administrative access is achieved—and combined with HFS’s server_code configuration, remote code execution (RCE) over server-side JavaScript becomes possible.

A proof-of-concept script was released in September 2026, demonstrating exactly how this attack chain works in practice. Earlier in July, HFS issued a patch in version 3.2.1 to address the weakness—but many instances still run versions 3.0.0 through 3.2.0 and remain vulnerable.

Evidence of Exploitation & Threat Landscape

Security firms spotted exploitation attempts almost immediately after a public vulnerability disclosure on October 1, 2026. The targeting appears to come from an actor based in China, with attacks observed against U.S.-based hosts. The flaw followed on the heels of a prior HFS vulnerability from 2024 (CVE-2024-23692) that also saw wide abuse, including deployment of cryptocurrency miners, trojans, and malware called HATVIBE.

Tools powered by AI played key roles in detecting and reporting this latest vulnerability. A researcher used Anthropic’s Mythos model to aid in discovering the attack path from authentication bypass to RCE. The Python PoC further allowed security experts to validate its real world feasibility.

What Users Should Do Now

If you run any Rejetto HFS installation, check the version: any build earlier than 3.2.1 is exposed. Upgrading to 3.2.1 is critical. Consider reviewing whether server_code or similar features that allow execution of custom JavaScript are enabled—if so, disable or restrict them until you’re sure the signing key issue is resolved securely.

Additionally, monitor logs for unauthorized login responses, repeated failed access attempts, or suspicious requests tied to cookie forging. Network defenders should check for unusual outbound activity that might indicate compromised hosts in vulnerable environments.

This incident adds to a growing list of critical HFS bugs being actively weaponized. Let it serve as a vivid reminder: weak PRNGs—and the exposure of their output—are not theoretical risks; they grant real, dangerous power in attacker hands. Expect further audits of similar functionality across file servers and web tools in the coming months.