News Date: 2026-10-05
Internet scanners have begun searching for Rejetto HTTP File Server installations affected by CVE-2026-61500, a critical security weakness that turns predictable session data into a path toward administrative control and remote code execution.
Rejetto HFS is an open-source tool used to share files through a self-hosted web server. Its accessibility makes it useful to individuals and smaller organizations, but an exposed HFS instance may also provide attackers with a direct route into the system hosting it.
How the Vulnerability Works
Affected HFS versions generate the cryptographic key used to sign session cookies with JavaScript's Math.random function. That function was not designed to produce security-sensitive values. The application also exposes related random outputs to unauthenticated clients during the login process.
An attacker can collect several of these outputs, reconstruct the generator's internal state and recover the signing key. The recovered key can then be used to create a valid administrator session cookie without knowing an administrator's password.
Administrative access is especially dangerous because HFS includes a server-side scripting feature. Once attackers obtain control of the management environment, they can potentially execute commands, steal or delete hosted files, install malware and use the server as a foothold for reaching other systems.
Scanning Raises the Urgency
VulnCheck detected limited reconnaissance targeting the flaw after researchers released technical details and proof-of-concept code. The observed traffic does not yet prove widespread compromise, but it shows that attackers are evaluating publicly reachable systems.
Organizations should not treat small-scale scanning as a reason to delay. Public exploit information commonly moves from research activity to automated exploitation once criminals identify enough exposed targets.
Recommended Actions
- Upgrade immediately to HFS 3.2.1 or, preferably, the latest stable release.
- Remove unnecessary HFS installations from direct internet exposure.
- Review administrative sessions, configuration changes and server-side scripts.
- Inspect affected hosts for unexpected processes, files and outbound connections.
- Restrict file-server access through firewalls, VPNs or trusted network ranges.
In my view, this case is a useful reminder that signing a session cookie is only as strong as the process used to generate the key. Authentication controls can appear cryptographically protected while still failing completely because of one predictable value underneath them.
