thehackernews.com 5 Oct 2026, 08:09 UTC

Rejetto HFS Flaw Lets Attackers Forge Admin Sessions and Run Code

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

A critical flaw in Rejetto HTTP File Server (HFS) tracked as CVE-2026-61500 is currently being exploited in the wild. The vulnerability stems from the way HFS derives its session-cookie signing key using the non-cryptographic Math[.]random() generator, and from the disclosure of PRNG outputs to unauthenticated clients during login. By collecting a few login responses, an attacker can reconstruct the PRNG state, recover the signing key, forge a valid administrator session, and gain full administrative access.

From there, remote code execution is possible via the server_code configuration feature, enabling the attacker to run server-side JavaScript with elevated privileges. The flaw affects HFS versions 3.0.0 through 3.2.0, with a patch released in version 3.2.1.

Independent researchers and security firms have documented the exploit path. Horizon3[.]ai’s Zach Hanley described it as an authentication bypass that enables arbitrary RCE, and a Python-based PoC disclosed by Alejandro Ramos (aka aramosf) corroborated the practical feasibility of forging an admin session and triggering code execution. VulnCheck reported exploitation attempts, noting the activity appeared to be originating from a threat actor in China targeting real vulnerable hosts in the United States. CVE-2026-61500 follows CVE-2024-23692 as the second Rejetto HFS vulnerability under active exploitation.

Organisations using Rejetto HFS should apply the 3.2.1 patch immediately, review login and admin-session activity for signs of forged cookies, and restrict exposure of administrative interfaces. While the article cites attackers rapidly moving to weaponise the flaw, verify all server_code configurations and monitor for unexpected JavaScript execution via HFS APIs.

View full article

Article by CyberSIXT