Full Report
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and
Analysis Summary
# Vulnerability: Session Forgery and RCE in Rejetto HFS
## CVE Details
- **CVE ID:** CVE-2026-61500
- **CVSS Score:** 9.3 (Critical)
- **CWE:** CWE-338 (Use of Cryptographically Weak Pseudo-Random Number Generator) / CWE-384 (Session Fixation/Forgery)
## Affected Systems
- **Products:** Rejetto HTTP File Server (HFS)
- **Versions:** 3.0.0 through 3.2.0
- **Configurations:** Systems utilizing the default session-cookie signing mechanism and the `server_code` configuration feature.
## Vulnerability Description
The vulnerability stems from the use of a non-cryptographic pseudo-random number generator (PRNG), specifically JavaScript’s `Math.random()`, to derive session-cookie signing keys. The server discloses outputs from this same V8 PRNG to unauthenticated clients during the Secure Remote Password (SRP) login handshake. By collecting a small number of these responses, a remote attacker can reconstruct the generator's internal state, recover the signing key, and forge a valid administrator session cookie.
## Exploitation
- **Status:** Exploited in the wild (active exploitation reported starting October 1, 2026).
- **PoC Available:** Yes (Python-based PoC released by researcher Alejandro Ramos).
- **Complexity:** Low (once the PRNG state is reconstructed).
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Full administrative access to files and server data).
- **Integrity:** High (Remote Code Execution via the `server_code` configuration feature).
- **Availability:** High (Total control over the server process and hosted services).
## Remediation
### Patches
- **Version 3.2.1:** Released in July 2026. Users are urged to upgrade immediately to this version or later.
### Workarounds
- Disable the `server_code` configuration feature if not strictly necessary to prevent the transition from session forgery to Remote Code Execution.
- Restrict access to the HFS administrative interface using firewall rules or IP whitelisting.
## Detection
- **Indicators of Compromise:**
- Unusually high volumes of login attempts or SRP handshake requests from a single IP.
- Unexpected administrative sessions originating from unknown or unauthorized IP addresses.
- Presence of unauthorized JavaScript within the `server_code` configuration.
- **Detection Methods:** Monitor web server logs for suspicious login patterns and audit server configuration changes for injected malicious code.
## References
- **Vendor Advisory:** [https://github[.]com/advisories/GHSA-xxrm-3f86-v97j]
- **Release Notes:** [https://github[.]com/rejetto/hfs/releases/tag/v3.2.1]
- **Researcher Disclosure:** [https://horizon3[.]ai/attack-research/disclosures/anthropic-mythos-rejetto-hfs-rce/]
- **PoC Repository:** [https://github[.]com/aramosf/CVE-2026-61500]