Rejetto HFS Attacks Exploit Predictable Session Signing to Reach Remote Code Execution
Active attacks exploit CVE-2026-61500 in Rejetto HFS 3.0.0-3.2.0, abusing weak session signing to forge admin access and run code. Update to 3.2.1.
Illustrative image generated with AI
VulnCheck has reported active exploitation attempts against vulnerable Rejetto HTTP File Server installations in the United States. The company detected the activity on October 1, 2026 and attributed it to an unnamed threat actor in China.
The attacks target CVE-2026-61500, a critical weakness in how HFS generates and protects session cookies. An unauthenticated attacker can potentially recover the signing key, create a valid administrator session and execute server-side JavaScript through the server_code configuration feature.
The available evidence confirms attempted exploitation against real, vulnerable hosts. It does not establish that the attempts resulted in successful compromises, and no affected organizations or victim counts have been identified in the supplied reporting.
Predictable randomness exposes the session-signing key
The vulnerability affects the HFS 3.x branch described by the advisory, specifically 3.0.0 through 3.2.0. It is classified as CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG).
HFS derives its session-cookie signing key from JavaScript’s non-cryptographic Math.random() generator. During unauthenticated login requests, the application also reveals values produced by that same generator.
This creates a path for remote key recovery. According to the vulnerability description, an attacker can collect a small number of login responses, reconstruct the pseudorandom generator’s internal state and derive the key used to sign session cookies.
Possession of that key allows the attacker to forge a cookie accepted by HFS as an authenticated administrator session. No legitimate account, stolen password or user interaction is required.
The impact extends beyond an authentication bypass. Once administrative access is obtained, the attacker can abuse HFS’s server_code configuration capability to run JavaScript on the server. Horizon3.ai researcher Zach Hanley also described the administrative API as allowing custom endpoints that execute arbitrary JavaScript.
The attack chain can therefore move directly from an unauthenticated network request to administrative control and remote code execution.
Exploitation attempts followed public technical details and a PoC
The vulnerability’s public record predates the observed attacks by several months. The GitHub Security Advisory GHSA-xxrm-3f86-v97j was published and updated on July 13, 2026. The advisory page also records NVD publication on that date.
On September 30, 2026, Hanley published an analysis characterizing the issue as an authentication bypass leading to arbitrary remote code execution. A news report said Anthropic’s Mythos model helped discover the flaw, but the available material does not independently demonstrate that AI-assisted discovery claim.
Security researcher Alejandro Ramos, also known as aramosf, reportedly released a Python proof of concept in late September 2026. The report attributes to Ramos the explanation that exposed V8 pseudorandom-generator outputs can be used to recover the signing key and construct an administrator session.
VulnCheck’s Patrick Garrity said the company detected exploitation attempts on October 1, 2026, one day after Horizon3.ai released additional technical details. VulnCheck described the source as an unnamed actor in China targeting vulnerable HFS systems in the United States.
That attribution remains VulnCheck’s assessment. The reporting does not name the operator, connect it to a recognized threat group or show that the observed requests achieved code execution.
Severity differs by scoring framework
The GitHub advisory assigns Critical severity and a 9.3/10 CVSS v4.0 score. Its complete vector is:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The base metrics describe a network-reachable attack with low complexity, no additional attack requirements, no privileges and no user interaction. Successful exploitation carries high confidentiality, integrity and availability impact for the vulnerable system.
The NVD data in our archive assigns 9.8 under CVSS v3.1, using this vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
These scores use different CVSS versions and should not be treated as conflicting measurements on the same scale.
The GitHub advisory also lists an EPSS score of 0.857%, placing the vulnerability in the 57th percentile. EPSS is a probability estimate rather than a severity rating, while VulnCheck’s observations provide separate evidence that exploitation is being attempted.
Version metadata leaves a verification gap
The advisory narrative identifies Rejetto HFS 3.0.0 through 3.2.0 as affected. However, its structured metadata gives both “Affected versions: Unknown” and “Patched versions: Unknown.”
A news report says Rejetto released the fix in HFS 3.2.1 in July 2026. The GitHub advisory links to the v3.2.1 release, although it does not formally designate that release as patched in its structured version field.
Administrators should therefore review Rejetto’s release information and verify the exact version deployed on each HFS server. Systems running 3.0.0 through 3.2.0, particularly those reachable from untrusted networks, warrant immediate attention.
The practical remediation described by the reporting is to upgrade to 3.2.1. Because of the discrepancy in the advisory metadata, operators should confirm that the selected package corresponds to Rejetto’s fixed release rather than relying solely on automated advisory fields.
The supplied GHSA material provides no workaround or detection indicators. The reporting likewise supplies no specific indicators of compromise or containment procedure; this limitation does not establish that none have been published elsewhere.
In the absence of report-specific indicators, defenders should prioritize version discovery and identify exposed HFS 3.x instances. They should also examine administrative changes and use of server_code where their existing logging makes that possible, without treating those checks as vendor-provided detection guidance.
An earlier HFS flaw already entered CISA’s exploited-vulnerability catalog
Rejetto has a separate history of exploitation involving CVE-2024-23692. That vulnerability is unrelated to the predictable session-signing process in CVE-2026-61500.
CVE-2024-23692 is a template-injection flaw allowing a remote, unauthenticated attacker to execute arbitrary commands through a crafted HTTP request. NVD’s description covers HFS through 2.3m and says that version was no longer supported as of the CVE assignment date. A separate NVD product field gives an upper boundary of ≤ 2.4; the available records do not reconcile those limits.
The older flaw has a 9.8 CVSS v3.1 score and is associated with CWE-1336 and CWE-94. Reporting described multiple actors exploiting it in July 2024 to deploy cryptocurrency miners, trojans and malware named HATVIBE.
CISA added CVE-2024-23692 to its Known Exploited Vulnerabilities catalog on July 9, 2024, with a federal remediation deadline of July 30, 2024. The record says it was used in ransomware campaigns.
CISA’s required action for that older flaw is: “Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.” That prescription applies to CVE-2024-23692 and is not a workaround for CVE-2026-61500.
For the newly targeted session-forgery vulnerability, the immediate operational priority is narrower: verify HFS versions, confirm the applicable Rejetto update and remediate exposed installations before attempted exploitation becomes a confirmed breach.
Sources
This article is an original reworking based on the sources below.
- primary sourceGitHub Security Advisory
- The Hacker News
CVEs covered in this article
- CVE-2024-23692Critical9.8Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment dat
- CVE-2026-61500Critical9.8Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's




