Skip to content
TrustList
News

Rejetto HFS session-forgery flaw CVE-2026-61500 now targeted by attackers: upgrade to 3.2.1 or later

Editorial

By TrustList Editorial

VulnCheck reports exploitation attempts against a critical Rejetto HFS flaw that lets an attacker forge administrator sessions and run code. HFS 3.2.1 fixed it on 13 July; versions 3.0.0 to 3.2.0 are reported as affected.

About Rejetto HFS session-forgery flaw CVE-2026-61500 now targeted by attackers: upgrade to 3.2.1 or later

Rejetto HFS session-forgery flaw CVE-2026-61500 now targeted by attackers: upgrade to 3.2.1 or later

5 October 2026 — Attackers have started probing a critical flaw in Rejetto HFS, the open-source HTTP File Server, according to VulnCheck. The vulnerability, tracked as CVE-2026-61500, lets an unauthenticated visitor forge an administrator session and then run code on the server. The fix has been available since 13 July 2026.

Not yet independently verified. The exploitation claim comes from VulnCheck as relayed by SecurityWeek; we did not read VulnCheck's or Horizon3.ai's own pages. The affected range (3.0.0 to 3.2.0) and the 9.3 score are VulnCheck's figures as reported by secondary sources. The HFS 3.2.1 release note does not name the CVE number. The Hacker News URL was taken from the outlet's front page link list and its text was not read in full. HFS 3.3.4 (30 September) is a separate security release; its contents are not described. We will update this when it can be confirmed, and remove this note.

What changed

SecurityWeek reports that HFS discloses outputs of its non-cryptographic session-cookie generator to unauthenticated clients during login, and derives the cookie signing key from the same generator. By collecting a small number of login responses, an attacker can reconstruct the generator's internal state, recover the signing key and forge valid administrator cookies. From an administrator session, the server's configuration features allow code execution. VulnCheck scores the flaw 9.3 out of 10.

Horizon3.ai found the weakness in June, using an AI model for the mathematical analysis, and published a technical write-up. On 2 October VulnCheck warned that small-scale reconnaissance against CVE-2026-61500 had begun from a China Telecom address and had touched its canary servers in Japan and the United States.

On the vendor side, the HFS 3.2.1 release of 13 July states that multiple security vulnerabilities existed in all previous versions and could allow an attacker to gain administrative access, and credits a Horizon3.ai researcher. A later release, 3.3.4 on 30 September, carries further security fixes from another reporter.

Who is affected

Anyone running HFS 3.0.0 to 3.2.0, which is the range VulnCheck gives. HFS is a lightweight file server often set up by individual teams for sharing builds, installers, media or documents, and it can be exposed to the internet without passing through central IT. Organisations that do not know whether such a server exists on their network are the most likely to be caught out. Public exposure matters more than size: a single forgotten instance reachable from the internet is enough.

What to do

  • Search for HFS instances on your network and public address ranges, including those run by project teams and contractors.
  • Upgrade to the current release. 3.2.1 is the first version fixed for this flaw; because 3.3.4 adds more security fixes, the newest stable version is the better target.
  • If an instance cannot be updated at once, take it off the internet or put it behind a VPN or an authenticating reverse proxy.
  • On any exposed instance running an affected version, treat the host as possibly compromised: review the server configuration for unexpected code settings, check for new administrator accounts, and rotate any credentials stored on or served from the machine.
  • Rotate session secrets after upgrading, so previously forged cookies stop working.

Why it matters

The flaw is a reminder that predictable random-number sources used for security tokens can be reversed. It is also a case of exploitation beginning within days of a public technical write-up, long after the patch was released. For buyers, the lesson is practical: patched does not mean deployed, and informal file-sharing tools are part of the attack surface that supplier and internal security reviews should cover.

Sources

Categories & features