Select a theme from the list.
Insights

From our experts

Latest
Emergency Exchange Update Closes a Door Into Other Users' MailboxesApple Moves to Rein In AI Agents With Sweeping Mac Data AccessPredictable Session Keys Put Rejetto File Servers on the Attack RadarMicrosoft X Account Hijack Shows How Brand Trust Can Become a Cyber WeaponFortra BoKS Flaws Put the Keys to Unix and Linux Fleets at RiskShinyHunters Detention Could Expose the People Behind a Global Extortion NetworkTerminalFix Lures Turn Victims Into Gateways for Covert Network AccessCritical Dell Storage Flaws Put Kubernetes Clusters and Backend Arrays at RiskDTU Identity System Breach Puts Two Decades of Personal Data at RiskPhishing Campaign Turns Legitimate RMM Software Into a Double BackdoorAndroid 17 Closes a Favorite Doorway for Banking MalwareFrontline Education Breach Exposes Sensitive School Employee RecordsEmergency Exchange Update Closes a Door Into Other Users' MailboxesApple Moves to Rein In AI Agents With Sweeping Mac Data AccessPredictable Session Keys Put Rejetto File Servers on the Attack RadarMicrosoft X Account Hijack Shows How Brand Trust Can Become a Cyber WeaponFortra BoKS Flaws Put the Keys to Unix and Linux Fleets at RiskShinyHunters Detention Could Expose the People Behind a Global Extortion NetworkTerminalFix Lures Turn Victims Into Gateways for Covert Network AccessCritical Dell Storage Flaws Put Kubernetes Clusters and Backend Arrays at RiskDTU Identity System Breach Puts Two Decades of Personal Data at RiskPhishing Campaign Turns Legitimate RMM Software Into a Double BackdoorAndroid 17 Closes a Favorite Doorway for Banking MalwareFrontline Education Breach Exposes Sensitive School Employee Records
Security Insight

Predictable Session Keys Put Rejetto File Servers on the Attack Radar

Predictable Session Keys Put Rejetto File Servers on the Attack Radar
Photo by Tima Miroshnichenko on Pexels

Security researchers have detected active scanning for a critical Rejetto HTTP File Server vulnerability that can let remote attackers forge administrator sessions and execute code. The weakness affects HFS versions 3.0.0 through 3.2.0 and has been corrected in newer releases.

News Date: 2026-10-05

Internet scanners have begun searching for Rejetto HTTP File Server installations affected by CVE-2026-61500, a critical security weakness that turns predictable session data into a path toward administrative control and remote code execution.

Rejetto HFS is an open-source tool used to share files through a self-hosted web server. Its accessibility makes it useful to individuals and smaller organizations, but an exposed HFS instance may also provide attackers with a direct route into the system hosting it.

How the Vulnerability Works

Affected HFS versions generate the cryptographic key used to sign session cookies with JavaScript's Math.random function. That function was not designed to produce security-sensitive values. The application also exposes related random outputs to unauthenticated clients during the login process.

An attacker can collect several of these outputs, reconstruct the generator's internal state and recover the signing key. The recovered key can then be used to create a valid administrator session cookie without knowing an administrator's password.

Administrative access is especially dangerous because HFS includes a server-side scripting feature. Once attackers obtain control of the management environment, they can potentially execute commands, steal or delete hosted files, install malware and use the server as a foothold for reaching other systems.

Scanning Raises the Urgency

VulnCheck detected limited reconnaissance targeting the flaw after researchers released technical details and proof-of-concept code. The observed traffic does not yet prove widespread compromise, but it shows that attackers are evaluating publicly reachable systems.

Organizations should not treat small-scale scanning as a reason to delay. Public exploit information commonly moves from research activity to automated exploitation once criminals identify enough exposed targets.

Recommended Actions

  • Upgrade immediately to HFS 3.2.1 or, preferably, the latest stable release.
  • Remove unnecessary HFS installations from direct internet exposure.
  • Review administrative sessions, configuration changes and server-side scripts.
  • Inspect affected hosts for unexpected processes, files and outbound connections.
  • Restrict file-server access through firewalls, VPNs or trusted network ranges.

In my view, this case is a useful reminder that signing a session cookie is only as strong as the process used to generate the key. Authentication controls can appear cryptographically protected while still failing completely because of one predictable value underneath them.

Talk to our team →

Latest

Emergency Exchange Update Closes a Door Into Other Users' MailboxesOct 6, 2026Apple Moves to Rein In AI Agents With Sweeping Mac Data AccessOct 6, 2026Predictable Session Keys Put Rejetto File Servers on the Attack RadarOct 6, 2026Microsoft X Account Hijack Shows How Brand Trust Can Become a Cyber WeaponOct 5, 2026Fortra BoKS Flaws Put the Keys to Unix and Linux Fleets at RiskOct 5, 2026ShinyHunters Detention Could Expose the People Behind a Global Extortion NetworkOct 5, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards