VulnCheck honeypots saw probes for CVE-2026-61500, a critical session-forgery bug in Rejetto HTTP File Server. It is scored 9.3. Versions 3.0.0 through 3.2.0 build the session-cookie signing key from a weak random generator and leak outputs of that same generator on the login path. An attacker can rebuild the key, forge an administrator cookie, and run server-side script through a built-in configuration feature.
What happened
Horizon3 found the chain with an AI model and published a write-up on 30 September 2026. VulnCheck saw scanning on 1 October. The activity so far is small: one China Telecom address probing canaries in Japan and the United States. VulnCheck has not reported confirmed compromise or follow-on malware from this wave. The technical details are public, so quiet servers will not stay quiet.
Who is affected
Anyone still running Rejetto HFS 3.0.0, 3.1.x, or 3.2.0, especially if the server is reachable from the internet. The fix landed in 3.2.1. The current stable line cited by researchers is 3.3.4.
- Vulnerable: HFS 3.0.0 through 3.2.0
- Minimum fix: 3.2.1
- Preferred current stable: 3.3.4
What to do now
Find every HFS instance and upgrade it. If you cannot upgrade today, remove it from the internet. A file server that can be turned into an admin shell is not a low-priority share. Check login logs for bursts of unauthenticated requests, then review server-side code settings for anything you did not put there.
Source: BleepingComputer, 5 October 2026. Rejetto HFS servers now actively scanned for critical RCE flaw.
Also on the blog
- Atlassian CVE-2026-21589: unauthenticated file read on 8 products
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- Exchange CVE-2026-96940: signed-in users can read other mailboxes
- ClickFix cache smuggling bypasses the Windows Run character limit
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.