Back to Newsroom
Threat Intel

Rejetto HFS Flaw Lets Attackers Forge Admin Sessions and Run Code

A critical flaw in Rejetto's popular file-server software lets remote attackers predict session keys, hijack admin accounts, and execute code — and it's already being exploited in the wild.

Rejetto HFS Flaw Lets Attackers Forge Admin Sessions and Run Code

A critical vulnerability in Rejetto HTTP File Server (HFS) is now being actively exploited in the wild, letting remote attackers forge administrator sessions and execute arbitrary code on exposed servers — with researchers tracing a likely China-based threat actor already scanning for victims in the US.

What happened

The flaw, tracked as CVE-2026-61500 (CVSS 9.3), affects HFS versions 3.0.0 through 3.2.0. The root cause is a classic cryptographic shortcut: the server generates the signing key for session cookies using JavaScript's Math.random() — a fast, convenient generator that was never designed to protect secrets. Worse, the same server leaks raw outputs from that generator to anyone attempting to log in, authenticated or not.

That combination turns out to be fatal. By collecting a handful of ordinary login attempts, an attacker can reconstruct the internal state of the random number generator, derive the exact signing key, and mint a forged administrator session cookie — no password required.

Once "logged in" as admin, the attacker can abuse HFS's server_code configuration feature — a legitimate admin capability that runs custom JavaScript on the server — to execute arbitrary code and take full control of the host.

Security researcher Zach Hanley at Horizon3.ai first flagged the flaw in a write-up published September 30, 2026, noting he used Anthropic's Mythos model to help uncover the bug and describing it as an authentication bypass that facilitates arbitrary remote code execution. Shortly after, researcher Alejandro Ramos (aramosf) published a working Python proof-of-concept, confirming the entire attack chain can be automated end-to-end.

Rejetto shipped a fix in version 3.2.1 back in July 2026, but the patch landed quietly enough that many installations appear to still be running vulnerable versions months later — exactly the gap attackers are now exploiting.

Why it matters

Within 24 hours of the technical details going public, threat-intel firm VulnCheck confirmed real-world exploitation attempts, pointing to an unnamed actor operating out of China and actively scanning for vulnerable HFS hosts in the United States.

This isn't Rejetto HFS's first brush with mass exploitation, either: a previous flaw, CVE-2024-23692 (CVSS 9.8), was weaponized throughout 2024 to deploy cryptocurrency miners, trojans, and custom malware. File-sharing tools like HFS are popular precisely because they're easy to stand up — which also means they're frequently left internet-facing on outdated versions with minimal monitoring, making them a reliable target the moment a working exploit goes public.

What to do

  • Update immediately — upgrade every Rejetto HFS instance to version 3.2.1 or later.
  • Check exposure — inventory any internet-facing HFS servers and confirm whether admin interfaces are reachable from the open internet; restrict access where possible.
  • Rotate sessions — after patching, invalidate existing session keys so any previously forged sessions are rendered useless.
  • Hunt for compromise — review logs for unexpected server_code executions, unfamiliar admin logins, or outbound traffic consistent with the China-linked scanning activity described above.
  • Lock down the admin API — disable or tightly restrict the server_code / custom-endpoint feature if it isn't actively needed, since it's the mechanism attackers use to turn a forged session into full code execution.
SHARE