Skip to main content

Rejetto HFS Weak Session Key Flaw Lets Attackers Forge Admin Sessions and Run Code, Scanning Has Started (CVE-2026-61500)

Scope: Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0

Severity: Red

CVE-2026-61500 (CVSS 9.3) is a session forgery flaw in Rejetto HFS, the free file-sharing server used on Windows, Linux, and macOS. HFS builds its session cookie signing key with JavaScript's Math.random(), which is not a cryptographic generator, and leaks outputs from the same generator to unauthenticated clients during login. An attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, forge an administrator session cookie, and then use HFS's built-in ability to run custom server-side JavaScript to execute code on the host. Horizon3 found the flaw using Anthropic's Mythos model and published a proof-of-concept exploit on September 30, 2026. VulnCheck's honeypots have since recorded small-scale probing, though no successful exploitation or post-exploitation activity has been reported. Once an attacker has admin access, they can read, steal, or delete shared files, install malware, or use the server to reach internal systems. Tools like this are often set up quickly to share files and then left running. Administrators must update to HFS 3.2.1 or later, ideally the latest stable release, 3.3.4, restrict access to trusted networks or a VPN, and review any HFS server that was internet-facing on an older version for unexpected admin activity and custom scripts.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.