Rejetto HFS servers are currently experiencing active scanning for a critical remote code execution (RCE) vulnerability, identified as CVE-2026-61500. This flaw, which allows for session forgery and account takeover, was first disclosed on July 13, 2026, and details of a proof-of-concept (PoC) exploit were publicly released on September 30, 2026.
Security researchers at VulnCheck observed initial reconnaissance activity targeting CVE-2026-61500 over the weekend of October 5, 2026, through their Canary Intelligence honeypot network. The observed probes originated from a single China Telecom IP address and appeared to be small-scale, focusing on deployments in Japan and the United States.
The vulnerability stems from a weak session-cookie signing key generation and leakage issue present in Rejetto HFS versions 3.0.0 through 3.2.0. The server derives its session-cookie signing key from the non-cryptographic `Math.random()` generator and inadvertently discloses outputs from this same generator to unauthenticated clients during the login process.
According to the NIST NVD description, a remote attacker can collect a limited number of login responses, subsequently reconstruct the state of the `Math.random()` generator, recover the signing key, and then forge a valid administrator session cookie. This grants full administrative access and enables remote code execution via the server's `server_code` configuration feature.
Horizon3 researchers discovered this flaw using Anthropic's Mythos model. The AI model not only identified the insecure pseudo-random number generator (PRNG) but also recognized that the application leaked raw `Math.random()` outputs through a separate code path. Mythos then connected these two facts, determining that the leaked data provided precisely the observations needed for state recovery.
The exploit developed by Horizon3 demonstrates how this chain of vulnerabilities can be abused to leverage HFS's built-in capability to execute custom server-side JavaScript, ultimately achieving remote code execution. Potential attack scenarios include unauthorized access, theft, or deletion of files, installation of malware on the server, or using the compromised host to gain access to internal systems.
While scanning activity has been confirmed, VulnCheck has not yet reported any instances of successful exploitation or subsequent post-exploitation actions. Rejetto HFS (HTTP File Server) is a free and open-source tool widely used for self-hosted file sharing across Windows, Linux, and macOS platforms.
Users of Rejetto HFS are strongly advised to upgrade to version 3.2.1, which contains the fix for CVE-2026-61500. Ideally, users should update to the latest stable release, version 3.3.4, as soon as possible to ensure comprehensive security.






