discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Rejetto HFS servers now actively scanned for critical RCE flaw

Hackers are actively scanning for a critical RCE vulnerability (CVE-2026-61500) in Rejetto HFS servers, allowing session forgery and account takeover.

By Bill Toulas·Oct 5·bleepingcomputer.com·2 min read

Intelligence analysis by Gemini 2.5 Flash Lite

A critical vulnerability in Rejetto HFS servers, CVE-2026-61500, is being actively scanned for by attackers. The flaw allows for session forgery and remote code execution by exploiting a weak signing key generation and leakage. Users are urged to update to the latest version.

Why it matters

This vulnerability allows attackers to gain full administrative access and execute arbitrary code on affected Rejetto HFS servers, posing a significant risk to data security and system integrity.

Imagine a secret code used to lock your online diary. This software used a very weak way to create the code, and it accidentally showed parts of it when people logged in. Hackers found a way to see those parts, figure out the whole code, and then read or change anything in the diary.

Analysis

CVE-2026-61500

The Rejetto HFS (HTTP File Server) software, a popular open-source tool for self-hosted file sharing, is currently facing active exploitation attempts due to a critical vulnerability identified as CVE-2026-61500. This flaw stems from a fundamental weakness in how the software generates and handles session cookies. Specifically, versions 3.0.0 through 3.2.0 of Rejetto HFS use a non-cryptographic random number generator, Math.random(), for deriving session-cookie signing keys. Compounding this issue, the application inadvertently leaks outputs from this same generator to unauthenticated clients during the login process.

Horizon3 Researchers

This critical vulnerability was brought to light by Horizon3 researchers, who utilized Anthropic's Mythos AI model to identify the exploit chain. The AI model was instrumental not only in flagging the insecure pseudo-random number generator (PRNG) but also in recognizing that the application's separate code path leaked the necessary raw Math.random() outputs. Horizon3's write-up details how this leak provided the exact observations needed to reconstruct the generator's internal state, thereby enabling the recovery of the session signing key. This discovery was further validated by a proof-of-concept (PoC) exploit released on September 30, 2026, which demonstrates the abuse of HFS's built-in server-side JavaScript execution capabilities to achieve remote code execution.

VulnCheck Canary Intelligence

Following the public disclosure of the vulnerability and the release of the PoC, security firms have observed active scanning for vulnerable servers. VulnCheck's Canary Intelligence honeypots detected probes targeting CVE-2026-61500, originating from a single China Telecom IP address and targeting deployments in Japan and the United States. While the observed activity is described as small-scale reconnaissance, it signifies a clear intent by threat actors to exploit this weakness. Potential attack scenarios include unauthorized access, modification, or deletion of files, deployment of malware, or using the compromised server as a pivot point into internal networks. Users are strongly advised to upgrade to Rejetto HFS version 3.2.1 or later, ideally the latest stable release, 3.3.4, to mitigate these risks.

Key points

  • Rejetto HFS servers are being actively scanned for a critical RCE vulnerability, CVE-2026-61500.
  • The flaw allows attackers to forge session cookies and gain administrative control.
  • Horizon3 researchers discovered the vulnerability using AI and released a proof-of-concept.
  • VulnCheck honeypots have detected reconnaissance probes targeting vulnerable servers.
  • Users are strongly advised to upgrade to Rejetto HFS version 3.2.1 or later.
The Upside

Prompt patching by users and the availability of updated software versions can effectively neutralize the threat posed by CVE-2026-61500. Swift adoption of these patches will prevent attackers from exploiting this vulnerability, ensuring the continued security of file-sharing operations.

The Downside

If users fail to update their Rejetto HFS servers promptly, attackers could successfully compromise administrative access, leading to data theft, system disruption, or the use of compromised servers for further malicious activities.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityvulnerabilityrceopen-sourcefile-sharingcve-2026-61500

Author

Bill Toulas

Intelligence analysis by

Gemini 2.5 Flash Lite

Published

Oct 5, 2026

Source

bleepingcomputer.com

Share

Topics

securityvulnerabilityrceopen-sourcefile-sharingcve-2026-61500

Related

More from this desk

Oct 7·thehackernews.com

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, including a serious SSRF bug rated 10.0 on the CVSS scale.

Oct 7·bleepingcomputer.com

Microsoft Outlook to block MSIX attachments starting November

Microsoft Outlook to block MSIX attachments starting November 2026.

Oct 7·bleepingcomputer.com

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.

Oct 7·bleepingcomputer.com

Ransomware has a new target. Is your backup ready?

Ransomware groups are targeting backups, making them a new threat. IT leaders need to secure their backups to prevent data loss.