A critical flaw in Rejetto HTTP File Server (HFS) 3.x lets an unauthenticated attacker forge an administrator session and execute code on the host. Tracked as CVE-2026-61500 (CVSS 4.0: 9.3), it was disclosed by Horizon3.ai at the end of September, and VulnCheck reports probing and targeting of exposed instances starting October 1 — roughly a day after the technical details went public. Horizon3 says the bug was found with the help of Anthropic’s Mythos model.

What happened

HFS is a lightweight file-sharing server popular for ad hoc transfers, which means it frequently sits directly on the internet with little hardening. This is the second HFS bug to draw real-world exploitation after CVE-2024-23692 (template injection, CVSS 9.8), which was used in 2024 to deliver miners, trojans and the HATVIBE malware.

VulnCheck’s honeypots recorded small-scale reconnaissance from a China Telecom IP against canaries in Japan and the US, and the firm also identified a China-based actor going after real vulnerable US hosts. A weaponized exploit is public in VulnCheck’s XDB. Early reporting disagreed on whether in-the-wild compromise was confirmed; treat the exposure as live either way.

Technical details

HFS 3.0.0 through 3.2.0 derive the key used to sign session cookies from Math.random(), which in V8 is an xorshift128+ generator and not a cryptographic RNG. Compounding the problem, the server returns raw outputs of that generator to unauthenticated clients during login. The chain is:

  1. Send a handful of login requests and collect the leaked PRNG outputs.
  2. Recover the internal xorshift128+ state from those outputs (a standard, solvable problem).
  3. Reproduce the signing key that the Koa session layer uses.
  4. Forge a valid administrator session cookie.
  5. Use HFS’s server_code configuration option, which accepts server-side JavaScript, to run arbitrary code as the HFS process user.

No credentials, user interaction or special configuration are required. The weakness class is CWE-338 (use of a cryptographically weak PRNG).

VulnCheck’s CNA record also covers two companion issues fixed in the same release:

  • CVE-2026-61501 — stored XSS in the admin log viewer.
  • CVE-2026-61502 — state-changing API calls reachable via GET, bypassing the anti-CSRF check.

Impact

Any internet-reachable HFS 3.0.0–3.2.0 instance should be considered compromisable. Code execution runs as the HFS service account; on Windows desktops and small servers, where HFS is often launched by a regular user or as a service with broad rights, that frequently means a foothold for lateral movement, data theft from the shared directory, or deployment of miners and loaders. Because the forged session is indistinguishable from a legitimate admin login at the cookie level, access logs alone may not reveal compromise.

Mitigation

  • Upgrade to HFS 3.2.1 (released July 13, 2026), which fixes all three CVEs.
  • Invalidate sessions and rotate secrets. After upgrading, restart the service, change the administrator password and treat any previously derived signing key as burned.
  • Remove the admin interface from the internet. If you cannot upgrade immediately, restrict the admin UI to a management network or VPN, or take HFS offline.
  • Hunt for tampering. Review the HFS configuration for unexpected server_code content, new admin accounts or plugins, and check the host for child processes spawned by the HFS binary, new scheduled tasks or services, and outbound connections from the file server.
  • Inventory. Search asset lists and external attack-surface scans for HFS banners; ad hoc file servers are a classic shadow-IT blind spot.

Why it matters

The pattern here — a secret derived from a non-cryptographic RNG whose output is also exposed to the client — is old, but it was only noticed in a widely deployed project once AI-assisted code auditing was pointed at it. Expect more of these: the gap between patch release (July 13), public technical write-up (end of September) and first scanning (October 1) shows how quickly an old fix becomes a fresh target once details land, especially for software that rarely gets updated.

References