Rejetto HTTP File Server versions 3.0.0 through 3.2.0 can be taken over without a password. CVE-2026-61500 lets an unauthenticated attacker forge an administrator session cookie and then run server-side JavaScript.
What happened
HFS derives its Koa session-cookie signing key from JavaScript Math.random() and leaks outputs of the same generator during the unauthenticated login handshake. A remote attacker can collect a small number of login responses, rebuild the generator state, recover the key, and sign a cookie that the server accepts as admin.
From there the documented server_code setting executes attacker JavaScript in the server process. Horizon3.ai researcher Zach Hanley found the bug with Anthropic's Mythos model. The fix shipped in HFS 3.2.1 in July 2026. A public proof of concept followed in late September. VulnCheck's Patrick Garrity said exploitation attempts were seen on 1 October 2026, including a China-based actor hitting real hosts in the United States. CVSS is 9.3 on version 4.0 and 9.8 on version 3.1.
Who is affected
- Rejetto HFS 3.0.0 through 3.2.0. Version 3.2.1 and later are the patched line.
- Any instance reachable from the internet, or from a network an attacker can already touch. No login is required.
- File-sharing boxes left on a DMZ, a lab VLAN, or a contractor jump host are the usual misses. This is the second exploited HFS flaw after CVE-2024-23692.
What to do now
Upgrade exposed HFS to 3.2.1 or later, or take it offline until you do. Then review admin actions and the server_code configuration for snippets you did not put there. A forged session does not need a stolen password, so password resets alone will not clear it.
Source: The Hacker News, citing the VulnCheck advisory and Horizon3.ai. Attackers target Rejetto HFS flaw that enables admin session forgery and RCE. Record: CVE-2026-61500.
Also on the blog
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- Google OSS VRP paused 1 October after AI bug-report flood
- CVE-2026-102489: Zammad session flaw chained to root, due 5 October
- CVE-2026-105215: ZITADEL Login V1 account pre-hijack, CVSS 9.1
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.