Security researchers are seeing exploitation attempts against CVE-2026-61500, a critical Rejetto HFS vulnerability that can give an unauthenticated attacker full administrative access and remote code execution. The flaw carries a CVSS 4.0 score of 9.3 and affects current-generation HFS 3.x installations.
The activity appeared shortly after researchers published technical details of the vulnerability. HFS operators running vulnerable versions should upgrade immediately and review internet-facing servers for suspicious activity.
VulnCheck said its Canary Intelligence began observing exploitation on Oct. 1 and added CVE-2026-61500 to its own Known Exploited Vulnerabilities database. Its Target Intelligence platform identified roughly 100 internet-facing HFS instances.
How CVE-2026-61500 leads to remote code execution
Rejetto HFS, or HTTP File Server, is open-source software used to share files over HTTP.
The vulnerability affects HFS 3.0.0 through 3.2.0 and stems from the way those releases generated the signing key used for session cookies. According to VulnCheck's advisory, HFS derived the key from JavaScript's non-cryptographic Math.random() generator while also exposing outputs from the same pseudorandom number generator to unauthenticated clients during login.
An attacker can collect login responses, reconstruct the generator's internal state, recover the session-signing key, and forge a valid administrator session cookie.
Administrative access then provides a route to remote code execution through HFS's built-in server_code configuration feature.
The vulnerability does not require valid credentials. VulnCheck's CVSS 4.0 vector rates it as remotely exploitable with low attack complexity, no privileges, and no user interaction, with high impact to confidentiality, integrity, and availability.
Horizon3, which discovered the issue with Anthropic's Mythos model, described an end-to-end attack chain that starts by confirming the built-in admin account exists and collecting outputs from the unauthenticated login process.
Researchers then use those values to reconstruct the state of V8's xorshift128+ pseudorandom number generator, recover the signing key, forge an administrative cookie, and use the resulting access to execute code on the server.
Horizon3 said Mythos identified both the weak random-number generation and the separate data leak needed to make state recovery practical.
Which HFS versions are vulnerable
CVE-2026-61500 affects:
- HFS 3.0.0 through 3.2.0: ✖ Vulnerable
- HFS 3.2.1 and later: ✔ Fixed
HFS 3.2.1 was the first version to address the issue. The fix replaces the predictable signing key with 32 bytes generated through Node.js randomBytes() and replaces the exposed numeric login identifier with a UUID.
Rejetto has released several newer versions since then. Its current release page lists HFS 3.3.4 as the latest stable build as of Oct. 6.
Administrators do not need to remain on 3.2.1 specifically. Systems should move to a current supported release unless compatibility requirements dictate otherwise.
The vulnerability affects the HFS 3.x codebase. Older HFS 2.x installations have separate security problems and should not be treated as affected by the same flaw.
HFS has previously been targeted in real attacks
Rejetto HFS has a history of attracting attacks against internet-facing servers.
A separate vulnerability, CVE-2024-23692, affects the end-of-life HFS 2.x branch. CISA added that flaw to its Known Exploited Vulnerabilities catalog in July 2024 after confirming active exploitation.
In 2025, Imperva observed more than 662 exploit attempts against CVE-2024-23692 across 55 customer domains over several days.
Attackers attempted to deploy ransomware and trojan malware through the older server-side template injection flaw. Imperva identified malicious downloaders, a ransomware sample, and command-and-control infrastructure associated with the activity.
CVE-2024-23692 and CVE-2026-61500 are separate vulnerabilities affecting different HFS branches. The older campaign does not establish what attackers are doing with CVE-2026-61500 today, but it demonstrates that exposed HFS servers have previously been targeted after exploitable weaknesses became public.
What defenders should do now
Organizations running HFS should first identify which major version and exact build are exposed.
For HFS 3.x:
- Upgrade any HFS 3.0.0 through 3.2.0 installation to 3.2.1 or a later supported release.
- Confirm the updated build is actually running after deployment.
- Restrict internet exposure where public access is not required.
- Review HFS and host logs for unusual authentication activity, configuration changes, or unexpected processes.
- Check for unauthorized administrator access and changes to
server_code. - Review credentials and other services reachable from the HFS host if suspicious activity is discovered.
For HFS 2.x, organizations should retire or isolate the software. Imperva notes that the branch is end-of-life and no longer receives security fixes.
Operators that cannot upgrade CVE-2026-61500 immediately can reduce exposure by supplying a strong explicit COOKIE_SIGN_KEYS value, which prevents prediction of the signing key. The published vulnerability analysis still recommends upgrading as the primary remediation.
VulnCheck's observation means defenders should no longer treat CVE-2026-61500 as a theoretical vulnerability. The affected version range is narrow, a fixed release has been available since July, and exploitation activity is now being detected.
Also read: Security teams managing internet-facing appliances should also review the latest NetScaler SAML zero-day, which requires newer patches even on some systems updated for earlier September vulnerabilities.





