CVE-2026-61500: Rejetto HFS admin session forgery, CVSS 9.3
Rejetto HFS Math.random session cookie signing key forgery

CVE-2026-61500: Rejetto HFS admin session forgery, CVSS 9.3

Rejetto HTTP File Server versions 3.0.0 through 3.2.0 can be taken over without a password. CVE-2026-61500 lets an unauthenticated attacker forge an administrator session cookie and then run server-side JavaScript.

What happened

HFS derives its Koa session-cookie signing key from JavaScript Math.random() and leaks outputs of the same generator during the unauthenticated login handshake. A remote attacker can collect a small number of login responses, rebuild the generator state, recover the key, and sign a cookie that the server accepts as admin.

From there the documented server_code setting executes attacker JavaScript in the server process. Horizon3.ai researcher Zach Hanley found the bug with Anthropic's Mythos model. The fix shipped in HFS 3.2.1 in July 2026. A public proof of concept followed in late September. VulnCheck's Patrick Garrity said exploitation attempts were seen on 1 October 2026, including a China-based actor hitting real hosts in the United States. CVSS is 9.3 on version 4.0 and 9.8 on version 3.1.

Who is affected

  • Rejetto HFS 3.0.0 through 3.2.0. Version 3.2.1 and later are the patched line.
  • Any instance reachable from the internet, or from a network an attacker can already touch. No login is required.
  • File-sharing boxes left on a DMZ, a lab VLAN, or a contractor jump host are the usual misses. This is the second exploited HFS flaw after CVE-2024-23692.

What to do now

Upgrade exposed HFS to 3.2.1 or later, or take it offline until you do. Then review admin actions and the server_code configuration for snippets you did not put there. A forged session does not need a stolen password, so password resets alone will not clear it.

Source: The Hacker News, citing the VulnCheck advisory and Horizon3.ai. Attackers target Rejetto HFS flaw that enables admin session forgery and RCE. Record: CVE-2026-61500.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

DTU breach: IAM data on up to 200,000 users
Technical University of Denmark identity store downloaded