DKDKCISSPSearch
Vulnerabilities

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.

DKCISSP News DeskThe Hacker News5 Oct 2026, 1:39 pm
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.

The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and seize control of affected systems.

Horizon3.ai researcher Zach Hanley, in a post published on September 30, 2026, said Anthropic's Mythos model was used to discover the vulnerability, describing it as an authentication bypass that facilitates arbitrary remote code execution on Rejetto HFS.

A patch for the vulnerability was released in July 2026 in version 3.2.1 .

However, it was not until late September that a Python-based proof-of-concept (PoC) exploit was publicly released by a security researcher named Alejandro Ramos (aka aramosf).

The cybersecurity company said it identified an unnamed threat actor in China targeting real vulnerable hosts in the U.S. CVE-2026-61500 is the second vulnerability in Rejetto HTTP File Server after CVE-2024-23692 (CVSS score: 9.8) to come under active exploitation in the wild.

According to VulnCheck's Patrick Garrity, exploitation attempts were detected on October 1, 2026, a day after Horizon3.ai published additional details of the flaw.

In July 2024, multiple threat actors were observed weaponizing the flaw to deliver cryptocurrency miners, trojans , and a malware named HATVIBE .

What happened

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.

The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and seize control of affected systems.

Horizon3.ai researcher Zach Hanley, in a post published on September 30, 2026, said Anthropic's Mythos model was used to discover the vulnerability, describing it as an authentication bypass that facilitates arbitrary remote code execution on Rejetto HFS.

What changed

A patch for the vulnerability was released in July 2026 in version 3.2.1 .

However, it was not until late September that a Python-based proof-of-concept (PoC) exploit was publicly released by a security researcher named Alejandro Ramos (aka aramosf).

The cybersecurity company said it identified an unnamed threat actor in China targeting real vulnerable hosts in the U.S. CVE-2026-61500 is the second vulnerability in Rejetto HTTP File Server after CVE-2024-23692 (CVSS score: 9.8) to come under active exploitation in the wild.

Technical details

According to VulnCheck's Patrick Garrity, exploitation attempts were detected on October 1, 2026, a day after Horizon3.ai published additional details of the flaw.

In July 2024, multiple threat actors were observed weaponizing the flaw to deliver cryptocurrency miners, trojans , and a malware named HATVIBE .

Attribution

The Hacker News: A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN VULNERABILITIES

More cybersecurity reporting

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOTThe Hacker News · 5 Oct 2026, 1:00 pmCVE-2023-36025 (SmartScreen Bypass) Vulnerability: Analysis & Detection | HuntressHuntress · 4 Oct 2026, 5:30 amCritical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pm