Critical Vulnerability in Rejetto HFS Exploited by Threat Actors, Warns VulnCheck
A critical vulnerability in Rejetto HTTP File Server (HFS) is being actively exploited by threat actors to gain remote code execution and bypass authentication. The flaw, tracked as CVE-2026-61500 with a CVSS score of 9.3, was discovered by Horizon3.ai researchers using an AI-powered model, and it affects all previous versions of the software.
The vulnerability exists because Rejetto HFS’s session cookie generator discloses sensitive information to unauthenticated clients during login. This allows attackers to reconstruct the generator’s state and recover the signing key, which can then be used to forge valid administrator session cookies. With these cookies, an attacker can gain elevated access to the server and execute malicious code.
The issue lies in Rejetto HFS’s use of the Math.random() function to generate random values for signing session cookies. The algorithm used by this function is reversible, making it possible for attackers to recover the secret signing key. Horizon3 explained that with a small set of collected login responses, an attacker can determine other generated numbers and forge authentication cookies.
The security firm discovered the weakness in June and notified Rejetto, which released version 3.2.1 on July 13 with patches addressing the issue. However, VulnCheck has now warned that threat actors have begun targeting this vulnerability as part of small-scale reconnaissance efforts originating from a China Telecom IP. The attempts have been detected hitting canaries in Japan and the US.
This incident highlights the importance of using secure random number generators (PRNGs) to protect sensitive information. It also underscores the value of AI-powered tools in identifying vulnerabilities that might otherwise go unnoticed. As cybersecurity threats continue to evolve, it’s essential for organizations to stay vigilant and keep their software up-to-date with the latest security patches.
In light of this incident, we recommend that Rejetto HFS users take immediate action to patch their systems and ensure they are running version 3.2.1 or later. Additionally, any organization using open-source file servers should review their configuration settings and consider implementing additional security measures to prevent similar vulnerabilities in the future. By staying proactive and informed about emerging threats, we can better protect our networks and systems from exploitation.
Source: SecurityWeek — 2026-10-05