Rejetto HFS servers now actively scanned for critical RCE flaw

A Critical Flaw in Rejetto HFS Servers is Being Actively Scanned by Hackers

Hackers have been spotted actively scanning for a critical vulnerability in Rejetto HFS servers, which allows them to gain full administrative access and execute remote code on compromised systems. The weakness, tracked as CVE-2026-61500, was first identified in July this year and has since been fixed in the latest version of the software.

Rejetto HFS is a popular open-source file-sharing server tool used by individuals and organizations to share files over the internet. However, its security has come under scrutiny due to the presence of the critical flaw. According to Caitlin Condon, VP of Security Research at VulnCheck, the company’s honeypot servers have observed small-scale reconnaissance activity from a single IP address in China targeting deployments of Rejetto HFS in Japan and the United States.

The vulnerability, which affects versions 3.0.0 through 3.2.0 of Rejetto HFS, is caused by the software’s use of a non-cryptographic random number generator to derive session-cookie signing keys. This weakness allows attackers to collect login responses from clients, reconstruct the generator’s state, and recover the signing key. With this information, hackers can forge valid administrator session cookies, granting them full access to the compromised server.

The discovery of the flaw was made possible by a combination of artificial intelligence (AI) and manual analysis. Horizon3 researchers used Anthropic’s Mythos model to identify both the weak signing-key generation and the leak that enabled key recovery. The researchers also published a proof-of-concept exploit demonstrating how attackers can use the vulnerability to achieve remote code execution.

The release of this technical information has likely prompted the current scanning activity targeting CVE-2026-61500. If exploited, the vulnerability could allow hackers to access, steal, or delete files on the compromised server, install malware, or use the host as a launching point for further attacks.

To mitigate this risk, users are urged to upgrade their Rejetto HFS installations to version 3.2.1 or the latest stable release, 3.3.4, as soon as possible. It’s essential to note that VulnCheck has not reported any successful exploitation attempts, but the presence of probing activity suggests that attackers may be preparing for a potential exploit.

In light of this development, it’s crucial for all Rejetto HFS users to take immediate action and protect their servers from potential attacks.


Source: Bleeping Computer — 2026-10-05