Ethical Hacking News
A critical security flaw in the Rejetto HTTP File Server (HFS) has been discovered, which has been actively exploited by attackers. The vulnerability, identified as CVE-2026-61500, is a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key. This allows an attacker to gain unauthorized access to affected systems, ultimately leading to full administrative access and remote code execution via the server_code configuration feature. Read more about this vulnerability and how to protect your systems from exploitation.
A critical security flaw (CVE-2026-61500) has been discovered in Rejetto HTTP File Server (HFS), allowing attackers to gain full administrative access and remote code execution. The vulnerability is due to a weak pseudo-random number generator (PRNG) and can be exploited by attackers to gain unauthorized access to affected systems. Rejetto HFS versions 3.0.0 through 3.2.0 are particularly susceptible to this vulnerability. A patch for the vulnerability was released in version 3.2.1, but a proof-of-concept exploit was publicly released later. Exploitation attempts were detected on October 1, 2026, targeting real vulnerable hosts in the US. Organizations using Rejetto HFS must patch their systems and implement additional security measures to prevent exploitation of this vulnerability.
A critical security flaw in the Rejetto HTTP File Server (HFS) has been discovered, which has been actively exploited by attackers. The vulnerability, identified as CVE-2026-61500, is a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key. This allows an attacker to gain unauthorized access to affected systems, ultimately leading to full administrative access and remote code execution via the server_code configuration feature.
The Rejetto HFS 3.0.0 through 3.2.0 versions are particularly susceptible to this vulnerability, as they derive their session-cookie signing key from the non-cryptographic Math.random() generator and disclose outputs of the same generator to unauthenticated clients during login. This creates a perfect storm of vulnerabilities that an attacker can exploit to gain administrative control over the system.
Horizon3.ai researcher Zach Hanley, in a post published on September 30, 2026, described the vulnerability as an authentication bypass that facilitates arbitrary remote code execution on Rejetto HFS. Hanley noted that Rejetto HFS's administrative API allows for custom endpoints that can execute arbitrary JavaScript, providing a clear path from unauthenticated access to administrative control and ultimately, remote code execution.
A patch for the vulnerability was released in July 2026 in version 3.2.1, but it wasn't until late September that a Python-based proof-of-concept (PoC) exploit was publicly released by security researcher Alejandro Ramos (aka aramosf). Ramos noted that the vulnerability was caused by HFS generating its Koa session-cookie signing key with JavaScript Math.random() and exposing outputs from the same V8 PRNG in the unauthenticated SRP login handshake.
Patrick Garrity, of VulnCheck, stated that exploitation attempts were detected on October 1, 2026, a day after Horizon3.ai published additional details of the flaw. Garrity revealed that an unnamed threat actor in China was targeting real vulnerable hosts in the U.S. This marks the second vulnerability in Rejetto HTTP File Server after CVE-2024-23692 to come under active exploitation in the wild.
The CVE-2026-61500 vulnerability is a significant concern for organizations that use Rejetto HFS, as it can allow attackers to gain administrative access to systems and execute arbitrary JavaScript code. This highlights the importance of keeping software up-to-date and applying patches in a timely manner to prevent such vulnerabilities.
In conclusion, the discovery of the CVE-2026-61500 vulnerability in Rejetto HFS serves as a reminder of the importance of maintaining robust security measures to protect against such threats. Organizations must take immediate action to patch their systems and implement additional security measures to prevent exploitation of this vulnerability.
Related Information:
https://www.ethicalhackingnews.com/articles/Attackers-Target-Rejetto-HFS-Flaw-That-Enables-Admin-Session-Forgery-and-RCE-Leaving-Systems-Vulnerable-to-Exploitation-ehn.shtml
https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html
https://nvd.nist.gov/vuln/detail/CVE-2026-61500
https://www.cvedetails.com/cve/CVE-2026-61500/
Published: Mon Oct 5 05:16:07 2026 by llama3.2 3B Q4_K_M