Follow
Subscribe via Email!

Enter your email address to subscribe to this platform and receive notifications of new posts by email.

A Rejetto HFS Flaw Triggers Probes for Remote Code Execution

Rejetto HFS faces scanning from a China Telecom IP address after researchers disclosed CVE-2026-61500, a flaw allowing forged administrator cookies.
A dark digital illustration depicting the interface and file directory of Rejetto HTTP File Server software.

Threat hunters at VulnCheck reported that online scanners are probing internet-facing servers running Rejetto HFS to locate setups flawed by a login bypass tracked as CVE-2026-61500. Probes started shortly after teams posted exploit write-ups on September 30, 2026. The bug lets remote hackers bypass login checks and seize full admin control over self-hosted file servers. Canary Intelligence decoys saw early scouting traffic sent from China Telecom networks aimed at hosts in Japan and the United States [1].

What Triggered the Rejetto HFS Scans

The wave of scanning followed the public release of research showing how hackers can abuse CVE-2026-61500. VulnCheck vice president of research Caitlin Condon shared details on LinkedIn showing that the company’s Canary Intelligence honeypots caught targeted probes over the weekend. Activity looked like small-scale scouting from a single China Telecom IP address probing setups in Japan and the United States [1].

Hackers moved fast once proof-of-concept code spread online. VulnCheck expert Patrick Garrity said that exploit attempts were detected on October 1, 2026, just one day after Horizon3.ai posted its review of the bug. Security analyst Alejandro Ramos had also shared a Python-based exploit script on GitHub. That public release showed how a hacker can turn an insecure PRNG leak into illicit server access. With functional exploit code circulating freely across developer channels, automated bots began querying live IP ranges within hours to locate responsive servers running outdated software releases [2].

Security teams have seen similar patterns when hackers sought to exploit a WordPress flaw for code execution, but this campaign focuses on self-hosted file tools. VulnCheck analysts tracked an unnamed hacker in China scanning for live, unpatched servers located across American networks [1, 2]. It hasn’t seen confirmed post-exploit activity yet, but scouting often leads to wider breach attempts.

Diagram illustrating the Rejetto HFS remote code execution vulnerability workflow.
Technical visual outlining the remote code execution flaw in Rejetto HFS. (Credit: The Hacker News)

How Anthropic Mythos Found the Flaw

Finding the flaw showed a notable step in automated bug hunting. Horizon3.ai expert Zach Hanley said that the team uncovered the security bug using Anthropic’s Mythos model during defensive work. Rather than simply spotting a lone bug in code, the AI model traced how two separate flaws worked together to yield a full login bypass [1, 2].

Horizon3 said that Mythos tied together two distinct code actions that human auditors might easily examine alone without seeing their shared danger. As Horizon3 described in its write-up, “Mythos didn’t just flag the insecure PRNG in isolation – it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible” [1]. That finding showed how a logged-out visitor could observe known values from the server and rebuild the internal PRNG (pseudo-random number generator) state without needing valid login keys on the target host. By reconstructing that internal math state, the model demonstrated a full path to compromise that human reviewers had missed for months.

Hanley pointed out that admin rights give hackers broad power over the host. “Rejetto HFS’s administrative API allows for custom endpoints that can execute arbitrary JavaScript,” Hanley said. “Combined, this presented a clear path from unauthenticated access to administrative control, and ultimately, remote code execution” [2]. Finding that complete attack chain with Mythos gave defenders clear proof of how modern models can spot real security flaws.

Code walkthrough showing session key recovery methods.
Demonstration of session key recovery steps documented by Horizon3 researchers. (Credit: Horizon3 / BleepingComputer)

Session Forgery in Rejetto HTTP File Server

The core mechanism behind the weakness stems from simple secret values created during web sessions. According to an advisory on the NIST NVD, “Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login” [1]. That design flaw breaks the basic security premise of web session cookies.

Alejandro Ramos detailed how the login process quietly leaks those weak outputs to outside watchers. “HFS generated its Koa session-cookie signing key with JavaScript Math.random() and exposed outputs from the same V8 PRNG in the unauthenticated SRP login handshake,” Ramos said in his analysis [2]. The server relies on Koa code for cookie handling, but sending raw PRNG outputs during the SRP handshake lets an outside hacker gather enough samples to compute the secret signing key. Because the mathematical generator repeats its sequences predictably, collecting a handful of login exchanges provides all the data needed to calculate the key without alerting system administrators.

Once a hacker recovers that signing key, forging admin cookies becomes simple. The NIST NVD advisory explains that “A remote attacker can collect a small number of login responses, reconstruct the generator’s state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature” [1]. That setting lets users run server-side scripts, enabling outside visitors to read files, plant malware, or pivot into private local networks.

Cybersecurity research graphic representing exploit shifts across software releases.
Research graphic accompanying security analysis of server vulnerabilities. (Credit: The Hacker News)

Earlier Abuse and the 2024 Precedent

CVE-2026-61500 is the second major security flaw in Rejetto HFS to face live attacks by online hackers. The software earlier came under assault through CVE-2024-23692, a remote code execution bug that carried a CVSS score of 9.8. In July 2024, multiple threat actors weaponized that earlier weakness to deploy crypto miners, trojans, and a malware variant named HATVIBE [2].

That history shows why security teams track file server flaws so closely. Network teams faced similar urgency during F5 zero-day attacks targeting BIG-IP APM OAuth servers, where exposed admin panels quickly drew automated scans once working exploit code spread online. Because file servers often hold sensitive files or sit on the edge of business systems, running code on them gives hackers a handy foothold inside private networks. Once bad actors gain initial access to a storage host, they can pivot deeper into internal corporate subnets and deploy persistent secondary payloads [2].

The current flaw carries a CVSS score of 9.3, a high mark despite its multi-step key recovery process. VulnCheck hasn’t found proof that current scanning from China Telecom has actually breached target servers yet. But the swift shift from release on September 30 to live scanning on October 1 shows how fast threat groups integrate shared proof-of-concept code into their automated tools [1, 2].

Fixes for CVE-2026-61500 have been ready since summer, but unpatched servers remain exposed online. The project team issued a patch fixing the session signing flaw in version 3.2.1 back in July 2026, weeks before experts shared code write-ups. Admins running self-hosted file sharing on Windows, Linux, or macOS should check their setups to confirm they aren’t running flawed code between 3.0.0 and 3.2.0 [1].

Security analysts advise updating beyond the early patch for stability and defense against related bugs. BleepingComputer reported that users of Rejetto HFS should upgrade to version 3.2.1 or, ideally, move straight to the latest stable release, version 3.3.4, as soon as possible [1]. Moving to current releases closes the weak PRNG leak and makes session cookies use sound signing keys. In addition to closing the session forgery gap, recent updates introduce performance improvements and bug fixes that help self-hosted servers resist external tampering during automated scanning waves.

Installing updated software stops hackers from abusing custom JavaScript endpoints through the admin API. Server admins who can’t update promptly can limit access to login portals by placing servers behind access control lists or virtual private networks. VulnCheck’s Canary Intelligence decoys keep watching global networks for further probing traffic, and admins should review access logs for odd requests hitting their login pages [1, 2].

Sources
  1. ONLINE NEWS Toulas, B. (2026, October 5). Rejetto HFS servers now actively scanned for critical RCE flaw. BleepingComputer. [Article Link]
  2. ONLINE NEWS The Hacker News. (2026, October 5). Attackers target Rejetto HFS flaw that enables admin session forgery and RCE. The Hacker News. [Article Link]

Leave a Comment

Related Posts
Total
0
Share