A Critical Flaw in Rejetto HFS Servers is Now Being Actively Scanned by Hackers
In a concerning development, hackers have started actively scanning for a critical remote code execution (RCE) flaw in Rejetto HFS servers. This weakness, tracked as CVE-2026-61500, allows attackers to forge session cookies, take control of accounts, and execute malicious code on the server. The vulnerability is particularly alarming because it can be exploited even if the server’s password is changed.
The scanning activity has been detected by VulnCheck’s Canary Intelligence honeypots, which have identified probes targeting CVE-2026-61500 from a single IP address in China Telecom. The observed activity appears to be small-scale reconnaissance, with hackers probing deployments in Japan and the United States. This suggests that attackers may be preparing for a more significant attack on vulnerable servers.
The flaw itself is related to how Rejetto HFS generates session cookies. The application uses the Math.random() function, which is not cryptographically secure, to derive its signing key. When an attacker collects a few login responses from the server, they can reconstruct the generator’s state and recover the signing key. This enables them to forge a valid administrator session cookie and gain full control over the server.
The vulnerability was first discovered by Horizon3 researchers using Anthropic’s Mythos model, which identified both the weak signing-key generation and the leak that enabled key recovery. The researchers published a detailed write-up of the flaw and provided a proof-of-concept exploit on September 30, 2026. This release may have prompted hackers to start actively scanning for vulnerable servers.
The potential consequences of exploiting this vulnerability are severe. Attackers could use the compromised server to access, steal, or delete files, install malware, or even use it as a stepping stone to access internal systems. However, VulnCheck has not shared any information on successful exploitation or post-exploitation activity.
To protect themselves from this threat, Rejetto HFS users are recommended to upgrade their servers to version 3.2.1 or the latest stable release, 3.3.4, as soon as possible. This will ensure that their servers are patched against CVE-2026-61500 and other known vulnerabilities.
The incident highlights the importance of staying up-to-date with security patches and best practices in server management. As AI-powered attacks become more common, it’s essential for organizations to build robust security blueprints that can detect and respond to these threats at machine speed.
Source: Bleeping Computer — 2026-10-05