Attackers are actively exploiting a critical flaw in Rejetto’s HTTP File Server that lets them forge administrator login cookies and gain full remote code execution, according to a disclosure published October 5 covering exploitation that began four days earlier.
The vulnerability, tracked as CVE-2026-61500 and rated 9.3 on the CVSS scale, affects HFS versions 3.0.0 through 3.2.0. It stems from how the software signs session cookies — a design flaw that gives attackers a direct path to administrative control without ever needing valid credentials.
Weak Random Number Generator Exposes Session Cookies
HFS signs its session cookies using Math.random(), a non-cryptographic pseudo-random number generator not designed to resist prediction. An attacker who collects a small number of login responses from a vulnerable server can reconstruct the generator’s internal state, recover the signing key, and use it to forge a valid administrator session cookie — effectively logging in as an admin without a password.
Once an attacker holds a forged admin session, they gain access to HFS’s administrative API. That API allows an authenticated administrator to define custom endpoints that execute arbitrary JavaScript on the server, which gives an attacker holding a forged session the same capability: full remote code execution on the host running HFS.
From Public Proof-of-Concept to Active Exploitation
Public proof-of-concept exploit code for CVE-2026-61500 was released in late September. Real-world exploitation against vulnerable, internet-facing U.S.-based HFS hosts began October 1, reportedly carried out by a threat actor based in China. The gap between proof-of-concept release and active exploitation was short, consistent with how quickly attackers typically weaponize publicly available exploit code against widely deployed file-sharing software.
Rejetto shipped version 3.2.1 in July, which fixes the underlying weak-cookie-signing flaw. That means a patch has been publicly available for roughly three months, yet enough vulnerable instances remain exposed online that the campaign starting October 1 was able to find and compromise them.
A Repeat Target: HFS’s Second Critical Flaw Under Attack
This is not the first time Rejetto’s file server software has been caught up in active exploitation. A prior HFS vulnerability, CVE-2024-23692, was previously exploited in the wild to deliver cryptocurrency miners, trojan malware, and the HATVIBE malware family. The recurrence of critical, actively exploited flaws in the same product shows the exposure risk that comes with running internet-facing file-sharing software without a disciplined patch cycle.
Why Session-Signing Flaws Are Especially Dangerous
The mechanics of CVE-2026-61500 illustrate a broader category of risk: authentication systems that rely on predictable random number generation rather than cryptographically secure generation. Where a cryptographically secure random number generator would make recovering the signing key computationally infeasible, Math.random() implementations in many programming environments are explicitly documented as unsuitable for security-sensitive operations because their internal state can be reconstructed from a limited number of outputs. When that weak generator underpins session authentication — rather than some lower-stakes feature — the consequence is a direct path from cookie forgery to full administrative compromise, as this flaw demonstrates.
Security researchers have long flagged predictable random number generation as a recurring root cause in authentication bypass vulnerabilities across many types of software, not just file servers. The pattern in HFS reflects that broader history: a convenience-oriented design choice, made without anticipating adversarial scrutiny, that ultimately became a critical vulnerability years after the software’s initial release.
Upgrading to HFS 3.2.1 Remains the Only Fix
Any internet-facing HFS instance still running a version between 3.0.0 and 3.2.0 is at risk of complete administrative takeover and arbitrary code execution through unauthenticated session forgery. Because the attack requires only observing a handful of legitimate login responses, exposure does not depend on any additional misconfiguration beyond running a vulnerable version with the service reachable from the internet.
Organizations running affected HFS versions should upgrade to 3.2.1 or later immediately. The patch has been available since July, but the exploitation campaign now underway demonstrates that a meaningful population of servers remains unpatched more than two months after the fix shipped. For administrators who cannot upgrade immediately, taking internet-facing HFS instances offline or restricting access to trusted networks would remove the precondition attackers need to collect the login responses required to forge a session.
The involvement of a China-based threat actor in the current campaign, combined with HFS’s history of being used to deliver cryptomining and trojan payloads, suggests the current wave of compromise could extend beyond simple access into follow-on malware deployment on compromised hosts, mirroring the pattern seen in the CVE-2024-23692 campaign.
