Exploitation of Rejetto HFS Flaw CVE-2026-61500 Begins

Attackers Actively Exploit Critical RCE Flaw in Rejetto HFS

CRITICAL
October 5, 2026
4m read
VulnerabilityCyberattack

Related Entities

Organizations

Rejetto VulnCheckHorizon3.ai

Products & Tech

Rejetto HFS

CVE Identifiers

CVE-2026-61500
CRITICAL
CVSS:9.3

Full Report

Executive Summary

A critical vulnerability in the Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, is under active exploitation by threat actors. The vulnerability, which has a CVSS score of 9.3, allows an unauthenticated remote attacker to achieve remote code execution (RCE). The flaw is due to the use of a weak, predictable random number generator (Math.random()) for creating the session cookie signing key. Attackers can reverse-engineer this key, forge an administrator cookie, and take complete control of the server. Security researchers have observed exploitation attempts targeting vulnerable HFS instances, prompting an urgent call for users to update to the patched version, HFS 3.2.1.

Vulnerability Details

CVE-2026-61500 is a session forgery vulnerability that leads to RCE. The root cause is a cryptographic weakness in how HFS generates its secret key for signing session cookies. The server uses Math.random(), a non-cryptographically secure pseudo-random number generator (PRNG), to seed this key.

The attack proceeds as follows:

  1. Information Leak: The HFS login page inadvertently leaks outputs from the same Math.random() generator to unauthenticated clients.
  2. State Reconstruction: An attacker can make a small number of requests to the login page to collect these random numbers. Because the PRNG is weak, this is enough information to reconstruct the internal state of the generator.
  3. Key Recovery: Once the generator's state is known, the attacker can predict its future outputs, including the secret value used to sign session cookies.
  4. Cookie Forgery: With the secret key, the attacker can now forge a valid session cookie for the admin user.
  5. Remote Code Execution: The attacker uses their forged admin session to access the server's administrative panel and leverages the server_code feature to execute arbitrary commands on the underlying server.

Affected Systems

  • Rejetto HFS versions 3.0.0 through 3.2.0 are vulnerable. The patched version is Rejetto HFS 3.2.1, released on July 13, 2026.

Exploitation Status

Active exploitation began shortly after technical details and a proof-of-concept were published by security researchers. The security firm VulnCheck, which discovered the flaw, has confirmed observing a threat actor based in China actively scanning for and exploiting vulnerable HFS servers, with targets identified in the United States. This indicates that any unpatched, internet-facing HFS instance is at high and immediate risk of compromise.

Impact Assessment

The impact of this vulnerability is critical. Successful exploitation gives an attacker full administrative control over the HFS server, which translates to RCE on the host operating system. An attacker can steal all files hosted on the server, modify server content, or use the compromised server as a pivot point to attack the internal network. Given that HFS is often used for simple file sharing, it may be deployed in less-secure environments without robust monitoring, making it an attractive target for attackers looking for an easy foothold. Compromised servers could be co-opted into botnets, used to host malware, or serve as a launchpad for ransomware attacks.

IOCs — Directly from Articles

No specific IOCs were provided in the source articles.

Cyber Observables — Hunting Hints

The following patterns may help identify vulnerable systems or exploitation attempts:

Type
url_pattern
Value
/
Description
Multiple, rapid requests to the root login page from a single IP can indicate an attempt to collect random numbers.
Context
Web server access logs
Type
command_line_pattern
Value
server_code
Description
Monitor for changes to the HFS configuration that involve the server_code parameter, especially if they contain shell commands.
Context
File integrity monitoring on HFS config files
Type
process_name
Value
Unusual child processes of hfs.exe.
Description
A successful RCE will likely spawn a shell or other processes under the HFS server process.
Context
EDR, Process creation logs (Event ID 4688)
Type
network_traffic_pattern
Value
Outbound connections from the HFS server to unknown IPs.
Description
Could indicate a reverse shell or C2 connection after compromise.
Context
Firewall logs, NetFlow data

Detection & Response

  1. Version Scanning: Use vulnerability scanners or asset inventory tools to identify all instances of Rejetto HFS in your environment and check if they are running a vulnerable version (3.0.0 to 3.2.0).
  2. Log Analysis: Analyze HFS and web server logs for rapid, repeated requests to the login page from a single IP address, which is a key indicator of the initial information gathering phase of the attack. D3-WSAA: Web Session Activity Analysis
  3. Process Monitoring: Monitor the HFS server for any suspicious child processes. The HFS process should not normally be spawning command shells (cmd.exe, powershell.exe, sh). D3-PA: Process Analysis

Remediation Steps

  1. Update Immediately: The primary and most urgent action is to update all Rejetto HFS instances to version 3.2.1 or later. This version replaces the weak PRNG with a cryptographically secure one, fully remediating the vulnerability. M1051 - Update Software
  2. Restrict Access: If an immediate update is not possible, restrict access to the HFS server to trusted IP addresses only. Do not expose HFS servers to the public internet unless absolutely necessary. M1035 - Limit Access to Resource Over Network
  3. Assume Compromise: If you find a vulnerable, internet-facing HFS server, assume it has been compromised. Isolate the server from the network and conduct a full forensic investigation to look for signs of persistence, malware, or lateral movement.

Timeline of Events

1
July 13, 2026
Rejetto releases HFS version 3.2.1, patching CVE-2026-61500.
2
October 1, 2026
Active exploitation of CVE-2026-61500 is detected in the wild.
3
October 5, 2026
This article was published

MITRE ATT&CK Mitigations

Immediately updating to HFS version 3.2.1 is the only way to fully remediate this vulnerability.

Mapped D3FEND Techniques:

As a temporary measure, restrict network access to the HFS server to only trusted IPs.

Mapped D3FEND Techniques:

While not a direct fix, application control policies could prevent the HFS server from executing unauthorized shells or malware after compromise.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

The most critical and immediate action for any organization using Rejetto HFS is to apply the available patch. All instances of HFS versions 3.0.0 through 3.2.0 must be upgraded to version 3.2.1 or later. This is not a routine update; it is an emergency change due to active, in-the-wild exploitation of a critical RCE vulnerability. An asset inventory system or vulnerability scanner should be used to urgently identify all HFS instances across the enterprise. Priority should be given to any server exposed to the internet. Patching directly fixes the root cause of CVE-2026-61500 by replacing the weak random number generator with a cryptographically secure one, thus preventing attackers from being able to forge administrator sessions.

For detection and threat hunting, Process Analysis is key. Since exploitation of CVE-2026-61500 leads to RCE, defenders must monitor the HFS server process (e.g., hfs.exe) for anomalous behavior. Specifically, use an EDR or enable process creation logging (Windows Event ID 4688) to watch for the HFS process spawning any child processes that are command interpreters. This includes cmd.exe, powershell.exe, sh, bash, or any other script execution engine. The HFS server should never be doing this during normal operation. An alert on such an event is a high-confidence indicator of compromise and should trigger an immediate incident response, including isolating the host from the network.

Timeline of Events

1
July 13, 2026

Rejetto releases HFS version 3.2.1, patching CVE-2026-61500.

2
October 1, 2026

Active exploitation of CVE-2026-61500 is detected in the wild.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

VulnerabilityRCERejetto HFSCVE-2026-61500Active Exploitation

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.