Hackers scanning for critical Rejetto HFS flaw allowing full server takeover

CVE-2026-61500 exploits weak session signing key; active reconnaissance spotted from China Telecom IP

By LineZotpaper
Published
Read Time2 min
Attackers are actively scanning for a critical vulnerability in Rejetto HTTP File Server (HFS) that could allow remote attackers to forge admin sessions and execute arbitrary code, security researchers warn. The flaw, tracked as CVE-2026-61500, affects HFS versions 3.0.0 through 3.2.0 and was discovered by Horizon3 using Anthropic's Mythos AI model. The vulnerability has been patched in version 3.2.1, and users are urged to upgrade immediately.

Researchers at VulnCheck have observed probes targeting the vulnerability, with a single China Telecom IP address conducting reconnaissance on deployments in Japan and the United States. The activity appears to be small-scale scanning so far, but the release of technical details and a proof-of-concept exploit by Horizon3 on September 30, 2026, may have prompted the interest.

The flaw stems from HFS's use of the non-cryptographic Math.random() generator to derive session-cookie signing keys, while simultaneously leaking outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie. This grants full administrative access, including the ability to execute code via the server_code configuration feature.

"Mythos didn't just flag the insecure PRNG in isolation – it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible," explained Horizon3 in their disclosure.

Attack scenarios include accessing, stealing, or deleting files on the HFS server, installing malware, or using the compromised host to pivot to internal networks. VulnCheck has not yet reported successful exploitation or post-exploitation activity. Users are recommended to upgrade to version 3.2.1 or, ideally, the latest stable release, 3.3.4.

§

Analysis

Why This Matters

  • Rejetto HFS is widely used for self-hosted file sharing, particularly in small businesses and home networks. A successful exploit could give attackers full control over affected servers, leading to data theft or malware deployment.
  • The active scanning indicates threat actors are moving quickly to weaponize the vulnerability, making patching urgent.
  • The discovery of the flaw by an AI model (Anthropic's Mythos) highlights the growing role of AI in vulnerability research, potentially accelerating both discovery and exploitation timelines.

Background

HTTP File Server (HFS) is a free, open-source tool for sharing files over HTTP, popular for its simplicity and cross-platform support (Windows, Linux, macOS). It is often used as a lightweight alternative to full-fledged file servers. Security flaws in such tools can have outsized impact because they are frequently deployed without rigorous patch management. The CVE-2026-61500 vulnerability is particularly dangerous because it chains a weak random number generator with an information leak, enabling full remote code execution.

Key Perspectives

Security researchers (VulnCheck, Horizon3): The flaw represents a serious risk that requires immediate patching. The scanning activity validates their concern and underscores the importance of timely updates. They praise the AI-assisted discovery as a demonstration of advanced threat detection. Rejetto HFS users: Many may be unaware of the update or may delay patching. The exploit's simplicity and the availability of a PoC increase pressure on administrators to act quickly. Critics/Skeptics: Some may argue that the scanning activity is routine and not yet indicative of widespread attacks. However, the release of an exploit PoC significantly lowers the barrier for even unskilled attackers.

What to Watch

  • Whether scanning evolves into active exploitation, particularly targeting vulnerable servers in Japan and the US.
  • Adoption rate of the patched versions 3.2.1/3.3.4 by HFS users.
  • Further disclosures or tooling that automates exploitation of CVE-2026-61500.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.