[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_U4JC_UtFEI1wQPB5K7gcqY33mHV-MFnkc1ZkasNXiY":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"fed8746e-f0de-4680-8b91-a5f92c4dc7f9","Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE","attackers-target-rejetto-hfs-flaw-that-enables-admin-session-forgery-and-rce-00cd8a","A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and","A critical vulnerability (CVE-2026-61500) in Rejetto HTTP File Server (HFS) is being actively exploited, allowing attackers to forge admin sessions and achieve remote code execution. The flaw stems from a weak PRNG used for session cookie signing, enabling attackers to recover the signing key. A patch was released in July 2026, but exploitation attempts were detected in October 2026 by an unnamed threat actor in China targeting US hosts.","Attackers exploit Rejetto HFS flaw CVE-2026-61500 for admin session forgery and RCE.","Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE Ravie LakshmananOct 05, 2026Vulnerability \u002F Web Security A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and seize control of affected systems. \"Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login,\" according to an advisory for the flaw. \"A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature.\" Horizon3.ai researcher Zach Hanley, in a post published on September 30, 2026, said Anthropic's Mythos model was used to discover the vulnerability, describing it as an authentication bypass that facilitates arbitrary remote code execution on Rejetto HFS. \"Rejetto HFS's administrative API allows for custom endpoints that can execute arbitrary JavaScript,\" Hanley said. \"Combined, this presented a clear path from unauthenticated access to administrative control, and ultimately, remote code execution.\" A patch for the vulnerability was released in July 2026 in version 3.2.1. However, it was not until late September that a Python-based proof-of-concept (PoC) exploit was publicly released by a security researcher named Alejandro Ramos (aka aramosf). \"HFS generated its Koa session-cookie signing key with JavaScript Math.random() and exposed outputs from the same V8 PRNG in the unauthenticated SRP login handshake,\" Ramos noted. \"An attacker can reconstruct the PRNG state, recover the signing key, forge an administrator session, and use the documented server_code configuration feature to execute server-side JavaScript.\" According to VulnCheck's Patrick Garrity, exploitation attempts were detected on October 1, 2026, a day after Horizon3.ai published additional details of the flaw. The cybersecurity company said it identified an unnamed threat actor in China targeting real vulnerable hosts in the U.S. CVE-2026-61500 is the second vulnerability in Rejetto HTTP File Server after CVE-2024-23692 (CVSS score: 9.8) to come under active exploitation in the wild. In July 2024, multiple threat actors were observed weaponizing the flaw to deliver cryptocurrency miners, trojans, and a malware named HATVIBE. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, Cyber Attack, Vulnerability, Web Security ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members How Financial Services Companies Can Modernize Their Software Supply Chain US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Zero Trust for AI Agents Starts With Fixing Zero Visibility ⭐ Featured Resources Discover Hidden AI Agents and Lock Down Their Access — Get a Demo The CISO Playbook for Board-Ready Security Reporting The Browser Attacks Your Security Stack Is Missing 41 Cybersecurity Courses. One Week to Level Up Your Skills","https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fattackers-target-rejetto-hfs-flaw-that.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEiTCvFj7lVSH1eLS0oYdxqBa4wQkNQvuemuCAL5XqwKueywAUl8Fg6zY-5UT9cdx3fZZ81DHX_emE9JXthW_OfH-axyWn3bE5CpCp4CDs4HREWjv_1uBtt5iJE947S-Bkn-4Mn1Shwt1kV9FF4RO9Wa7_4jmUtvbWrx2zs4-cdSg-FkUtxW-erVx2CXKhU3\u002Fs1600\u002Fhfs-rce-main.jpg","2026-10-05T08:09:23+00:00","2026-10-05T10:00:15.091325+00:00",9,[18,21,24,27,29],{"name":19,"type":20},"HTTP File Server (HFS)","product",{"name":22,"type":23},"Rejetto","vendor",{"name":25,"type":26},"unnamed threat actor","threat_actor",{"name":28,"type":20},"Mythos",{"name":30,"type":23},"Anthropic","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":31,"icon":33,"name":34,"slug":35},null,"Vulnerabilities","vulnerabilities",[37,42,44],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":43},{"id":31,"icon":33,"name":34,"slug":35},{"category":45},{"id":46,"icon":33,"name":47,"slug":48},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[50,54],{"type":51,"value":52,"context":53},"cve","CVE-2026-61500","Rejetto HFS session forgery and RCE vulnerability",{"type":51,"value":55,"context":56},"CVE-2024-23692","Previous Rejetto HFS vulnerability exploited for malware delivery"]