A critical flaw in Rejetto HTTP File Server (HFS) 3.x lets an unauthenticated attacker forge an administrator session and execute code on the host. Tracked as CVE-2026-61500 (CVSS 4.0: 9.3), it was disclosed by Horizon3.ai at the end of September, and VulnCheck reports probing and targeting of exposed instances starting October 1 — roughly a day after the technical details went public. Horizon3 says the bug was found with the help of Anthropic’s Mythos model.
What happened
HFS is a lightweight file-sharing server popular for ad hoc transfers, which means it frequently sits directly on the internet with little hardening. This is the second HFS bug to draw real-world exploitation after CVE-2024-23692 (template injection, CVSS 9.8), which was used in 2024 to deliver miners, trojans and the HATVIBE malware.
VulnCheck’s honeypots recorded small-scale reconnaissance from a China Telecom IP against canaries in Japan and the US, and the firm also identified a China-based actor going after real vulnerable US hosts. A weaponized exploit is public in VulnCheck’s XDB. Early reporting disagreed on whether in-the-wild compromise was confirmed; treat the exposure as live either way.
Technical details
HFS 3.0.0 through 3.2.0 derive the key used to sign session cookies from Math.random(), which in V8 is an xorshift128+ generator and not a cryptographic RNG. Compounding the problem, the server returns raw outputs of that generator to unauthenticated clients during login. The chain is:
- Send a handful of login requests and collect the leaked PRNG outputs.
- Recover the internal xorshift128+ state from those outputs (a standard, solvable problem).
- Reproduce the signing key that the Koa session layer uses.
- Forge a valid administrator session cookie.
- Use HFS’s
server_codeconfiguration option, which accepts server-side JavaScript, to run arbitrary code as the HFS process user.
No credentials, user interaction or special configuration are required. The weakness class is CWE-338 (use of a cryptographically weak PRNG).
VulnCheck’s CNA record also covers two companion issues fixed in the same release:
- CVE-2026-61501 — stored XSS in the admin log viewer.
- CVE-2026-61502 — state-changing API calls reachable via GET, bypassing the anti-CSRF check.
Impact
Any internet-reachable HFS 3.0.0–3.2.0 instance should be considered compromisable. Code execution runs as the HFS service account; on Windows desktops and small servers, where HFS is often launched by a regular user or as a service with broad rights, that frequently means a foothold for lateral movement, data theft from the shared directory, or deployment of miners and loaders. Because the forged session is indistinguishable from a legitimate admin login at the cookie level, access logs alone may not reveal compromise.
Mitigation
- Upgrade to HFS 3.2.1 (released July 13, 2026), which fixes all three CVEs.
- Invalidate sessions and rotate secrets. After upgrading, restart the service, change the administrator password and treat any previously derived signing key as burned.
- Remove the admin interface from the internet. If you cannot upgrade immediately, restrict the admin UI to a management network or VPN, or take HFS offline.
- Hunt for tampering. Review the HFS configuration for unexpected
server_codecontent, new admin accounts or plugins, and check the host for child processes spawned by the HFS binary, new scheduled tasks or services, and outbound connections from the file server. - Inventory. Search asset lists and external attack-surface scans for HFS banners; ad hoc file servers are a classic shadow-IT blind spot.
Why it matters
The pattern here — a secret derived from a non-cryptographic RNG whose output is also exposed to the client — is old, but it was only noticed in a widely deployed project once AI-assisted code auditing was pointed at it. Expect more of these: the gap between patch release (July 13), public technical write-up (end of September) and first scanning (October 1) shows how quickly an old fix becomes a fresh target once details land, especially for software that rarely gets updated.
References
- NVD / VulnCheck CNA record: CVE-2026-61500, CVE-2026-61501, CVE-2026-61502
- OSV entry for CVE-2026-61500
- HFS v3.2.1 release
- The Hacker News coverage
- BleepingComputer coverage
- SecurityWeek coverage