CVE

CVE-2026-61500

Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key

Exploitation IoCs 2

GitHub User aramosf
IP 117[.]10[.]22[.]133

MITRE ATT&CK TTPs 7

Source Articles

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
A critical vulnerability, CVE-2026-61500, in Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0 is under active exploitation, enabling attackers to forge administrator session cookies and achieve remote code execution. The flaw stems from the use of a predictable pseudo-random number generator (Math.random()) for session-cookie signing keys, which can be reconstructed by unauthenticated attackers through login responses. A proof-of-concept exploit was publicly released by researcher Alejandro Ramos (aramosf), and exploitation attempts have been observed, including by an unnamed threat actor based in China targeting U.S. systems. The vulnerability follows previous exploitation of another Rejetto HFS flaw, CVE-2024-23692, which was used to deploy cryptocurrency miners and malware such as HATVIBE.
hacker-news Oct 5, 2026
Rejetto HFS servers now actively scanned for critical RCE flaw
Hackers are actively scanning for a critical remote code execution (RCE) vulnerability, CVE-2026-61500, in Rejetto HFS (HTTP File Server) instances. The flaw stems from a weak session-cookie signing key derived from JavaScript's Math.random() generator, which is also leaked to unauthenticated clients, enabling attackers to reconstruct the key and forge administrator session cookies. Successful exploitation allows full administrative access and remote code execution via server-side JavaScript execution. Probing activity has been observed from a single China Telecom IP address targeting systems in Japan and the United States, likely for reconnaissance ahead of broader exploitation.
bleeping-computer Oct 5, 2026