New Rejetto HFS Flaw Already Under Attack, Days After Disclosure
Security researchers have found a critical authentication-bypass vulnerability, tracked as CVE-2026-61500, in Rejetto HTTP File Server (HFS), a popular open-source tool used for sharing files over the web. The flaw can allow attackers to gain full administrative access and remotely execute code on vulnerable servers. HFS had already appeared on the US Cybersecurity and Infrastructure Security Agency's list of Known Exploited Vulnerabilities in 2024, highlighting a pattern of repeated real-world abuse.
The vulnerability was discovered using Anthropic's AI-powered bug-hunting tool, Mythos, and disclosed publicly along with details of how it could be exploited. Within a day, researchers at VulnCheck detected active exploitation attempts, with the first wave originating from an IP address in China and targeting servers in the US and Japan. By the following day, additional exploitation attempts were observed from US-based IP addresses believed to be routed through a proxy.
This incident underscores how quickly attackers move once technical details of a vulnerability become public, particularly when proof-of-concept exploitation steps are shared openly. Businesses running Rejetto HFS should treat this as an urgent patching priority.