Active Exploitation Targets Rejetto HFS Session Forgery Vulnerability

Attackers are actively attempting to exploit CVE-2026-61500, a critical vulnerability in Rejetto HTTP File Server (HFS) that can enable administrator session forgery and remote code execution. VulnCheck detected exploitation attempts on October 1, 2026, and said an unnamed threat actor in China was targeting real vulnerable hosts in the United States.
The flaw has a CVSS score of 9.3 and affects Rejetto HFS versions 3.0.0 through 3.2.0. Rejetto released a fix in HFS 3.2.1 in July 2026, before a public Python proof of concept appeared in late September.
Predictable session signing keys create an administrative path
The issue stems from HFS deriving the signing key for session cookies from JavaScript's non-cryptographic Math.random() generator. During the unauthenticated SRP login handshake, the server also exposes outputs from the same V8 pseudo-random number generator.
An attacker can collect a small number of login responses, reconstruct the generator state, recover the session-cookie signing key and forge a valid administrator session. With administrative access, the documented server_code configuration feature can be used to execute server-side JavaScript, creating a route from unauthenticated access to remote code execution.
Horizon3.ai researcher Zach Hanley described the weakness as an authentication bypass that enables arbitrary remote code execution. Hanley said the administrative API permits custom endpoints capable of running arbitrary JavaScript, turning the forged session into full administrative control of the server.
Public exploit details were followed by observed attacks
A security researcher, Alejandro Ramos, published a Python-based proof of concept in late September. Ramos said the combination of an exposed V8 PRNG output and a session signing key generated with Math.random() made it possible to recover the key and create an administrator session.
VulnCheck's Patrick Garrity said exploitation attempts were seen one day after Horizon3.ai published additional technical details on September 30. The speed of that activity underlines the operational risk for internet-accessible installations that remain on affected versions.
HFS administrators should establish patch status
CVE-2026-61500 is the second Rejetto HFS issue to face active exploitation after CVE-2024-23692, which has a CVSS score of 9.8. In July 2024, multiple threat actors used that earlier flaw to distribute cryptocurrency miners, trojans and HATVIBE malware.
Organizations using Rejetto HFS should determine whether any systems run versions 3.0.0 through 3.2.0 and move them to version 3.2.1. They should also review affected hosts for unauthorized administrator sessions and server-side configuration changes, because successful exploitation provides administrative access and a mechanism for server-side code execution.

