Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Attackers are exploiting Rejetto HFS CVE-2026-61500 to forge admin sessions and gain remote code execution.
VulnCheck reports active exploitation of CVE-2026-61500 (CVSS 9.3), a session-forgery flaw in Rejetto HTTP File Server 3.0.0 through 3.2.0. The product derives its session-cookie signing key from JavaScript Math.random() and exposes outputs of the same generator during unauthenticated login, allowing an attacker to recover the key, forge an administrator cookie, and execute arbitrary JavaScript via the server_code feature. A patch was released in version 3.2.1 in July 2026, and a public Python proof-of-concept appeared in late September. Exploitation attempts were detected on October 1, including a China-based actor targeting vulnerable US hosts; Horizon3.ai said Anthropic’s Mythos model was used to discover the bug.
- CVE-2026-61500, CVSS 9.3, allows forged Rejetto HFS administrator cookies.
- Math.random() session keys enable unauthenticated admin access and JavaScript RCE.
- Version 3.2.1 patched it in July 2026; a public PoC followed in September.
- VulnCheck saw October 1 exploitation of real US hosts by a China-based actor.
- Horizon3.ai said Anthropic’s Mythos model helped discover the flaw.
Vulnerabilities mentionedAll →
- CVE-2024-236929.899%Unauthenticated Template Injection RCE in Rejetto HTTP File Server 2.3mpublished · rejetto HTTP File Server KEV ransomware PoC ×5
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | horizon3.ai | code execution via the server_code configuration feature." Horizon3.ai researcher Zach Hanley, in a post published on September 30 |
Full article420 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 05, 2026Vulnerability / Web Security
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.
The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and seize control of affected systems.
"Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login," according to an advisory for the flaw.
"A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature."
Horizon3.ai researcher Zach Hanley, in a post published on September 30, 2026, said Anthropic's Mythos model was used to discover the vulnerability, describing it as an authentication bypass that facilitates arbitrary remote code execution on Rejetto HFS.
"Rejetto HFS's administrative API allows for custom endpoints that can execute arbitrary JavaScript," Hanley said. "Combined, this presented a clear path from unauthenticated access to administrative control, and ultimately, remote code execution."
A patch for the vulnerability was released in July 2026 in version 3.2.1. However, it was not until late September that a Python-based proof-of-concept (PoC) exploit was publicly released by a security researcher named Alejandro Ramos (aka aramosf).
"HFS generated its Koa session-cookie signing key with JavaScript Math.random() and exposed outputs from the same V8 PRNG in the unauthenticated SRP login handshake," Ramos noted. "An attacker can reconstruct the PRNG state, recover the signing key, forge an administrator session, and use the documented server_code configuration feature to execute server-side JavaScript."
According to VulnCheck's Patrick Garrity, exploitation attempts were detected on October 1, 2026, a day after Horizon3.ai published additional details of the flaw. The cybersecurity company said it identified an unnamed threat actor in China targeting real vulnerable hosts in the U.S.
CVE-2026-61500 is the second vulnerability in Rejetto HTTP File Server after CVE-2024-23692 (CVSS score: 9.8) to come under active exploitation in the wild. In July 2024, multiple threat actors were observed weaponizing the flaw to deliver cryptocurrency miners, trojans, and a malware named HATVIBE.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.