Last updated: October 5, 2026 at 10:28 AM UTC
All 897 Vulnerability 362 Breach 144 Threat 384 Defense 7
Tag: weak-prng (1 article)Clear

Attackers exploit Rejetto HTTP File Server session forgery flaw to gain code execution

VulnCheck reported active exploitation attempts against a critical Rejetto HTTP File Server flaw, CVE-2026-61500, rated 9.3. The vulnerability is session forgery stemming from a weak pseudo-random number generator: HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie. That yields full administrative access and remote code execution through the server_code configuration feature. Horizon3.ai described it as an authentication bypass enabling arbitrary code execution.

Check
Locate exposed Rejetto HFS 3.0.0 through 3.2.0 instances, update to a fixed release or take them off the public internet, and review for rogue admin sessions.
Affected
Rejetto HFS 3.0.0 through 3.2.0 lets a remote attacker recover the session signing key from login responses and forge an administrator cookie for code execution.
Fix
Patch or retire affected HFS instances, restrict access to trusted networks, and audit the server_code configuration and administrative sessions for abuse.