Rejetto file servers are being probed — upgrade HFS before the scans turn into break-ins

By George Bailey   Published: 10/06/26   4 min read

Somebody set up Rejetto HFS to share files “just for a bit,” and it is still answering on the internet. If it runs version 3.0.0 through 3.2.0, an attacker can forge an admin login without a password and run code on the box. A public exploit has been out since late September, and VulnCheck says the scanning started last week.

No password needed: a dozen login replies give away the admin key.

What happened

CVE-2026-61500 (CVSS 4.0 score 9.3) is a session-forgery flaw in Rejetto HTTP File Server, the free, open-source file-sharing server for Windows, Linux and macOS. HFS 3.0.0 through 3.2.0 builds the key that signs session cookies from JavaScript’s non-cryptographic Math.random(), and it leaks outputs from the same generator to anyone who starts a login. Collect a handful of those replies, rebuild the generator’s state, recover the signing key, and you can mint a valid administrator cookie. From there, HFS’s built-in server_code feature runs server-side JavaScript, which means remote code execution.

The fix shipped in HFS 3.2.1 on July 13, 2026. Exploitation details came later. Horizon3.ai published its write-up and proof of concept on September 30, saying it found the chain with Anthropic’s Mythos model. Researcher Alejandro Ramos also released a Python proof of concept in late September. VulnCheck says its honeypots saw exploitation attempts starting October 1: small-scale reconnaissance from a single China Telecom address, probing canary systems in Japan and the United States. VulnCheck has not reported a successful compromise or post-exploitation activity.

Why it matters

HFS has been through this before. An older bug, CVE-2024-23692, made CISA’s Known Exploited Vulnerabilities list and was used in 2024 to drop cryptocurrency miners and other malware. File servers like this tend to live on desks and side projects, outside the patch system. A public exploit plus active probing is usually the step before mass use.

What to do first

Forward this

If you run a small file-sharing server called HFS (Rejetto HTTP File Server): update it to 3.3.4, or at least 3.2.1, or unplug it from the internet today. Older 3.x versions can be taken over without a password, and attackers are already scanning for them.

Details

Hunt / verify

Slack paste: Rejetto HFS 3.0.0–3.2.0 can be taken over with no password (forged admin cookie, then RCE via server_code). Public PoC since Sep 30, scanning since Oct 1. Upgrade to 3.3.4 (min 3.2.1) or pull it off the internet. CVE-2026-61500.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.