Attackers Exploit Rejetto HFS Flaw That Lets Them Forge Admin Access
A critical vulnerability in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500 and rated 9.3 on the CVSS scale, is now being actively targeted, according to VulnCheck. The flaw affects HFS versions 3.0.0 through 3.2.0. It stems from the software using a weak, non-cryptographic random number generator to create the key that protects login session cookies.
According to the advisory, the server also reveals outputs from the same generator to unauthenticated visitors during login. A remote attacker can collect a small number of login responses, work out the key, and forge a valid administrator session. From there, a configuration feature allows the attacker to run code on the server, giving them full control. Horizon3.ai researcher Zach Hanley said Anthropic's Mythos model was used to discover the flaw.
A fix was released in July 2026 in version 3.2.1. However, a public proof-of-concept exploit written in Python appeared in late September, and Horizon3.ai published further details on September 30. VulnCheck's Patrick Garrity said exploitation attempts were detected on October 1, a day later. VulnCheck identified an unnamed threat actor in China targeting real vulnerable hosts in the U.S.