Skip to main content
Emerging Threats

Hackers Actively Scan Rejetto HFS Servers for Critical RCE Flaw

Rows of rack-mounted servers and storage units in a data center with cables and network equipment visible.

CVE-2026-61500, first published on July 13, 2026, is a Rejetto HFS flaw that allows session forgery, account takeover, and remote code execution.

CVE-2026-61500: a weak signing key and an information leak

The National Institute of Standards and Technology's National Vulnerability Database (NVD) describes CVE-2026-61500 as a session-cookie signing weakness combined with a leakage issue that was fixed in Rejetto HFS 3.2.1. According to the NVD, "Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login." The consequence, the NVD says, is that an attacker can "collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature."

VulnCheck Canary Intelligence: active probes observed from a China Telecom IP

VulnCheck's Vice President of Security Research, Caitlin Condon, posted on LinkedIn that the company's Canary Intelligence honeypots observed probes targeting CVE-2026-61500 over the weekend. Condon characterized the activity as "small-scale reconnaissance" originating from a single China Telecom IP address and noted targets in Japan and the United States. VulnCheck has not shared any details indicating successful exploitation or subsequent post-exploitation activity.

Horizon3, Anthropic's Mythos, and a public proof-of-concept

Horizon3 researchers found the vulnerability with assistance from Anthropic's Mythos model. Horizon3 said Mythos "didn't just flag the insecure PRNG in isolation – it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible." On September 30, 2026, Horizon3 published a write-up that included further technical details and a proof-of-concept exploit demonstrating the attack chain.

Attack scenarios and technical impact on affected hosts

Horizon3's exploit demonstrates how recovered signing keys can be used to forge an administrative session cookie and then leverage HFS's server_code configuration feature to execute arbitrary server-side JavaScript, achieving remote code execution (RCE). The public write-up and proof-of-concept make clear what is technically possible: an attacker with a forged admin session could access, steal, or delete files hosted by HFS, install malware on the server, or use the compromised host as a pivot to reach internal systems. The release of those technical details may have prompted the probing activity observed by VulnCheck.

What this means for Rejetto HFS users, security teams, and adversaries

  • Rejetto HFS users and administrators: The source recommendation is straightforward — upgrade to Rejetto HFS 3.2.1 (the version that fixes the weakness) or, preferably, the later stable release 3.3.4 as soon as possible.
  • Security teams and incident responders: Honeypots and telemetry already recorded probing activity; teams should look for evidence of the specific attack chain described by Horizon3 (login-response leakage, forged session cookies, server_code execution) and prioritize patching exposed HFS instances.
  • Adversaries and opportunistic attackers: The combination of a public proof-of-concept and observed reconnaissance activity creates a window in which low-effort scanning could find and compromise unpatched HFS servers.

The facts in hand are precise: a deterministic weakness in the use of Math.random(), an information leak that enables state recovery, a published proof-of-concept, and active scanning observed by a security vendor. The next concrete measure for defenders is likewise precise — apply the fixed releases (3.2.1 or 3.3.4) immediately and monitor for indicators tied to the login-response leak and forged administrator sessions. Whether the small-scale reconnaissance reported by VulnCheck widens into sustained exploitation remains to be seen, but the technical chain and an available exploit mean unpatched HFS servers are exposed now.

Original reporting: BleepingComputer — Rejetto HFS servers now actively scanned for critical RCE flaw