Rejetto HFS session-forgery flaw CVE-2026-61500 now targeted by attackers: upgrade to 3.2.1 or later
EditorialBy TrustList Editorial
VulnCheck reports exploitation attempts against a critical Rejetto HFS flaw that lets an attacker forge administrator sessions and run code. HFS 3.2.1 fixed it on 13 July; versions 3.0.0 to 3.2.0 are reported as affected.
- Cybersecurity
- Vulnerability Management
- File Sharing
About Rejetto HFS session-forgery flaw CVE-2026-61500 now targeted by attackers: upgrade to 3.2.1 or later
Rejetto HFS session-forgery flaw CVE-2026-61500 now targeted by attackers: upgrade to 3.2.1 or later
5 October 2026 — Attackers have started probing a critical flaw in Rejetto HFS, the open-source HTTP File Server, according to VulnCheck. The vulnerability, tracked as CVE-2026-61500, lets an unauthenticated visitor forge an administrator session and then run code on the server. The fix has been available since 13 July 2026.
Not yet independently verified. The exploitation claim comes from VulnCheck as relayed by SecurityWeek; we did not read VulnCheck's or Horizon3.ai's own pages. The affected range (3.0.0 to 3.2.0) and the 9.3 score are VulnCheck's figures as reported by secondary sources. The HFS 3.2.1 release note does not name the CVE number. The Hacker News URL was taken from the outlet's front page link list and its text was not read in full. HFS 3.3.4 (30 September) is a separate security release; its contents are not described. We will update this when it can be confirmed, and remove this note.
What changed
SecurityWeek reports that HFS discloses outputs of its non-cryptographic session-cookie generator to unauthenticated clients during login, and derives the cookie signing key from the same generator. By collecting a small number of login responses, an attacker can reconstruct the generator's internal state, recover the signing key and forge valid administrator cookies. From an administrator session, the server's configuration features allow code execution. VulnCheck scores the flaw 9.3 out of 10.
Horizon3.ai found the weakness in June, using an AI model for the mathematical analysis, and published a technical write-up. On 2 October VulnCheck warned that small-scale reconnaissance against CVE-2026-61500 had begun from a China Telecom address and had touched its canary servers in Japan and the United States.
On the vendor side, the HFS 3.2.1 release of 13 July states that multiple security vulnerabilities existed in all previous versions and could allow an attacker to gain administrative access, and credits a Horizon3.ai researcher. A later release, 3.3.4 on 30 September, carries further security fixes from another reporter.
Who is affected
Anyone running HFS 3.0.0 to 3.2.0, which is the range VulnCheck gives. HFS is a lightweight file server often set up by individual teams for sharing builds, installers, media or documents, and it can be exposed to the internet without passing through central IT. Organisations that do not know whether such a server exists on their network are the most likely to be caught out. Public exposure matters more than size: a single forgotten instance reachable from the internet is enough.
What to do
- Search for HFS instances on your network and public address ranges, including those run by project teams and contractors.
- Upgrade to the current release. 3.2.1 is the first version fixed for this flaw; because 3.3.4 adds more security fixes, the newest stable version is the better target.
- If an instance cannot be updated at once, take it off the internet or put it behind a VPN or an authenticating reverse proxy.
- On any exposed instance running an affected version, treat the host as possibly compromised: review the server configuration for unexpected code settings, check for new administrator accounts, and rotate any credentials stored on or served from the machine.
- Rotate session secrets after upgrading, so previously forged cookies stop working.
Why it matters
The flaw is a reminder that predictable random-number sources used for security tokens can be reversed. It is also a case of exploitation beginning within days of a public technical write-up, long after the patch was released. For buyers, the lesson is practical: patched does not mean deployed, and informal file-sharing tools are part of the attack surface that supplier and internal security reviews should cover.
Sources
- Rejetto HFS v3.2.1 release notes on GitHub — 13 July 2026
- Rejetto HFS v3.3.4 release notes on GitHub (further security fixes) — 30 September 2026
- SecurityWeek (citing VulnCheck and Horizon3.ai) — 5 October 2026
- The Hacker News — 5 October 2026
Categories & features
- Cybersecurity
- Vulnerability Management
- File Sharing
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.