A critical vulnerability in the Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, is under active exploitation by threat actors. The vulnerability, which has a CVSS score of 9.3, allows an unauthenticated remote attacker to achieve remote code execution (RCE). The flaw is due to the use of a weak, predictable random number generator (Math.random()) for creating the session cookie signing key. Attackers can reverse-engineer this key, forge an administrator cookie, and take complete control of the server. Security researchers have observed exploitation attempts targeting vulnerable HFS instances, prompting an urgent call for users to update to the patched version, HFS 3.2.1.
CVE-2026-61500 is a session forgery vulnerability that leads to RCE. The root cause is a cryptographic weakness in how HFS generates its secret key for signing session cookies. The server uses Math.random(), a non-cryptographically secure pseudo-random number generator (PRNG), to seed this key.
The attack proceeds as follows:
Math.random() generator to unauthenticated clients.admin user.server_code feature to execute arbitrary commands on the underlying server.3.0.0 through 3.2.0 are vulnerable.
The patched version is Rejetto HFS 3.2.1, released on July 13, 2026.Active exploitation began shortly after technical details and a proof-of-concept were published by security researchers. The security firm VulnCheck, which discovered the flaw, has confirmed observing a threat actor based in China actively scanning for and exploiting vulnerable HFS servers, with targets identified in the United States. This indicates that any unpatched, internet-facing HFS instance is at high and immediate risk of compromise.
The impact of this vulnerability is critical. Successful exploitation gives an attacker full administrative control over the HFS server, which translates to RCE on the host operating system. An attacker can steal all files hosted on the server, modify server content, or use the compromised server as a pivot point to attack the internal network. Given that HFS is often used for simple file sharing, it may be deployed in less-secure environments without robust monitoring, making it an attractive target for attackers looking for an easy foothold. Compromised servers could be co-opted into botnets, used to host malware, or serve as a launchpad for ransomware attacks.
No specific IOCs were provided in the source articles.
The following patterns may help identify vulnerable systems or exploitation attempts:
url_pattern/command_line_patternserver_codeserver_code parameter, especially if they contain shell commands.process_namehfs.exe.network_traffic_pattern3.0.0 to 3.2.0).D3-WSAA: Web Session Activity Analysiscmd.exe, powershell.exe, sh). D3-PA: Process Analysis3.2.1 or later. This version replaces the weak PRNG with a cryptographically secure one, fully remediating the vulnerability. M1051 - Update SoftwareM1035 - Limit Access to Resource Over NetworkImmediately updating to HFS version 3.2.1 is the only way to fully remediate this vulnerability.
Mapped D3FEND Techniques:
As a temporary measure, restrict network access to the HFS server to only trusted IPs.
Mapped D3FEND Techniques:
While not a direct fix, application control policies could prevent the HFS server from executing unauthorized shells or malware after compromise.
Mapped D3FEND Techniques:
The most critical and immediate action for any organization using Rejetto HFS is to apply the available patch. All instances of HFS versions 3.0.0 through 3.2.0 must be upgraded to version 3.2.1 or later. This is not a routine update; it is an emergency change due to active, in-the-wild exploitation of a critical RCE vulnerability. An asset inventory system or vulnerability scanner should be used to urgently identify all HFS instances across the enterprise. Priority should be given to any server exposed to the internet. Patching directly fixes the root cause of CVE-2026-61500 by replacing the weak random number generator with a cryptographically secure one, thus preventing attackers from being able to forge administrator sessions.
For detection and threat hunting, Process Analysis is key. Since exploitation of CVE-2026-61500 leads to RCE, defenders must monitor the HFS server process (e.g., hfs.exe) for anomalous behavior. Specifically, use an EDR or enable process creation logging (Windows Event ID 4688) to watch for the HFS process spawning any child processes that are command interpreters. This includes cmd.exe, powershell.exe, sh, bash, or any other script execution engine. The HFS server should never be doing this during normal operation. An alert on such an event is a high-confidence indicator of compromise and should trigger an immediate incident response, including isolating the host from the network.
Rejetto releases HFS version 3.2.1, patching CVE-2026-61500.
Active exploitation of CVE-2026-61500 is detected in the wild.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.