CVE
CVE-2026-61500
Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key
Exploitation IoCs 2
GitHub User aramosf
IP 117[.]10[.]22[.]133
MITRE ATT&CK TTPs 7
T1059 T1059.007 T1133 T1190 T1210 T1552 T1552.005
Command and Scripting Interpreter
Execution
JavaScript
Execution
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Exploitation of Remote Services
Lateral Movement
Unsecured Credentials
Credential Access
Cloud Instance Metadata API
Credential Access
Source Articles
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
A critical vulnerability, CVE-2026-61500, in Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0 is under active exploitation, enabling attackers to forge administrator session cookies and achieve remote code execution. The flaw stems from the use of a predictable pseudo-random number generator (Math.random()) for session-cookie signing keys, which can be reconstructed by unauthenticated attackers through login responses. A proof-of-concept exploit was publicly released by researcher Alejandro Ramos (aramosf), and exploitation attempts have been observed, including by an unnamed threat actor based in China targeting U.S. systems. The vulnerability follows previous exploitation of another Rejetto HFS flaw, CVE-2024-23692, which was used to deploy cryptocurrency miners and malware such as HATVIBE.
hacker-news Oct 5, 2026
Rejetto HFS servers now actively scanned for critical RCE flaw
Hackers are actively scanning for a critical remote code execution (RCE) vulnerability, CVE-2026-61500, in Rejetto HFS (HTTP File Server) instances. The flaw stems from a weak session-cookie signing key derived from JavaScript's Math.random() generator, which is also leaked to unauthenticated clients, enabling attackers to reconstruct the key and forge administrator session cookies. Successful exploitation allows full administrative access and remote code execution via server-side JavaScript execution. Probing activity has been observed from a single China Telecom IP address targeting systems in Japan and the United States, likely for reconnaissance ahead of broader exploitation.
bleeping-computer Oct 5, 2026