Rejetto HFS Weak PRNG Allows Admin Session Forgery and RCE
A critical flaw in Rejetto HTTP File Server stems from the use of a cryptographically weak Pseudo-Random Number Generator (PRNG) to sign session cookies, allowing attackers to mathematically recover the signing key and forge administrative sessions. Once admin access is obtained, attackers can achieve full Remote Code Execution on the host system. A patch was available in July 2026, yet active exploitation was not detected until October 2026 — a three-month window during which unpatched systems remained exposed. This incident highlights the danger of deploying internet-facing file-sharing services without rigorous patch cadence and cryptographic hygiene. The use of weak PRNGs in security-sensitive operations like session management is a foundational design flaw that should be caught during development and code review.
Tactical Insight
Immediate actions
- Patch all Rejetto HFS instances to the version released in July 2026 or later immediately.
- Audit internet-facing file server applications for weak or non-cryptographic PRNG usage in session handling.
- Temporarily restrict or firewall access to HFS instances until patching is confirmed complete.
Long-term improvements
- Establish a maximum 30-day SLA for applying critical patches to all internet-facing services.
- Maintain a continuously updated inventory of all externally exposed services to ensure no assets are missed during patch cycles.
- Enforce use of cryptographically secure random number generators (CSPRNGs) as a mandatory secure coding standard for all session token generation.
Detection measures
- Deploy anomaly detection rules to flag unusual admin session creation patterns or session cookie manipulation attempts.
- Monitor threat intelligence feeds for CVEs affecting deployed software and trigger automatic alerts when exploitation is reported in the wild.
- Review web server and application logs regularly for signs of session forgery, such as unexpected privilege escalation or admin logins from unknown IPs.