Attackers are probing CVE-2026-61500 in Rejetto HTTP File Server, SecurityWeek reported on 5 October 2026. The bug is unauthenticated session forgery. A forged administrator cookie leads to remote code execution through the server's own configuration feature.
What happened
HFS 3.0.0 through 3.2.0 derived its session-cookie signing key from JavaScript Math.random() and leaked outputs of the same generator to anyone who started a login. An attacker who collects a small set of those responses can rebuild the generator state, recover the key, and sign a valid administrator cookie. From there, the documented server_code setting runs server-side JavaScript.
The CVE record scores it 9.3 on CVSS 4.0 and 9.8 on CVSS 3.1. Horizon3.ai, working with Claude, found the flaw. A public proof of concept followed in late September. VulnCheck said exploitation attempts showed up on 1 October, including scans from a China Telecom address against canaries in Japan and the United States, and attempts against real hosts in the US. The fix is HFS 3.2.1, which switches the signing key to cryptographic random bytes.
Who is affected
Anyone still running Rejetto HFS 3.0.0, 3.1.x, or 3.2.0 on a reachable interface. File servers of this type often sit on a lab LAN, a client jump box, or a forgotten DMZ host rather than in a formal asset list. HFS 3.2.1 is the first fixed release.
What to do now
- Find every HFS instance and upgrade to 3.2.1. If you cannot patch today, take it off the network.
- Treat any unexpected administrator session since late September as a compromise, not a failed login.
- Check server_code and httpd-style config changes, plus new outbound connections from the host.
- Do not leave ad-hoc file servers on client sites without an owner and a patch path.
Source: SecurityWeek, 5 October 2026, citing VulnCheck and the CVE record. Read the report.
Also on the blog
- Denmark CPR breach: 8.8 million identity records
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- Zammad CVE-2026-102489: KEV due date is today
- ShinyHunters: suspected member detained in Jordan
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.