Full Report
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [...]
Analysis Summary
# Vulnerability: Rejetto HFS Weak Session Signing Key (RCE)
## CVE Details
- **CVE ID:** CVE-2026-61500
- **CVSS Score:** Not explicitly listed in the article, but characterized as **Critical** due to RCE capabilities.
- **CWE:** Weak PRNG (Pseudorandom Number Generator) / Insufficient Session Sealing.
## Affected Systems
- **Products:** Rejetto HFS (HTTP File Server)
- **Versions:** 3.0.0 through 3.2.0
- **Configurations:** Default deployments are vulnerable as the flaw resides in the core session-cookie signing mechanism.
## Vulnerability Description
The vulnerability stems from two combined flaws in Rejetto HFS:
1. **Weak Key Generation:** The application derives its session-cookie signing key using the non-cryptographic `Math.random()` generator.
2. **Information Leak:** Outputs from the same `Math.random()` generator are disclosed to unauthenticated clients during the login process.
A remote attacker can collect a small number of login responses to reconstruct the internal state of the generator. By recovering the signing key, the attacker can forge a valid administrator session cookie. This grants full administrative access, which can be leveraged for Remote Code Execution (RCE) via the application's `server_code` configuration feature (server-side JavaScript execution).
## Exploitation
- **Status:** **Exploited in the wild** (Active scanning/probing observed by VulnCheck honeypots as of October 2026).
- **PoC Available:** Yes (Published by Horizon3 on September 30, 2026).
- **Complexity:** Medium (Requires state recovery of the PRNG).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Full administrative access, ability to steal hosted files).
- **Integrity:** High (Ability to modify/delete files and execute arbitrary code).
- **Availability:** High (Ability to delete files or compromise the underlying server).
## Remediation
### Patches
- **Upgrade to Rejetto HFS version 3.2.1** (minimum version containing the fix).
- **Recommended:** Upgrade to the latest stable release, **version 3.3.4**, to ensure all subsequent security improvements are included.
### Workarounds
- No specific workarounds are provided in the text; immediate patching or decommissioning the service if it cannot be updated is advised.
## Detection
- **Indicators of Compromise:**
- Monitor for reconnaissance activity from China Telecom IP addresses.
- Unusual login patterns or multiple rapid requests to the login endpoint (used to collect PRNG outputs).
- Unauthorized changes to the `server_code` configuration.
- **Detection Methods:**
- Log analysis for administrative logins from unexpected IP addresses.
- Intrusion Detection Systems (IDS) signatures for known CVE-2026-61500 PoC payloads.
## References
- **Vendor Code:** hxxps[://]github[.]com/rejetto/hfs
- **NVD Entry:** hxxps[://]nvd[.]nist[.]gov/vuln/detail/cve-2026-61500
- **Horizon3 Research:** hxxps[://]horizon3[.]ai/attack-research/disclosures/anthropic-mythos-rejetto-hfs-rce/
- **Original Report:** hxxps[://]www[.]bleepingcomputer[.]com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/