Vulnerabilities & Exploits

Rejetto HFS Auth Bypass Hit Within a Day

VulnCheck said CVE-2026-61500 in Rejetto HTTP File Server was being probed in the wild by Thursday, just a day after Horizon3’s Zach Hanley disclosed the flaw in the open source file server. The first activity came from a China-hosted IP and targeted vulnerable hosts in the US and Japan.

The bug is an authentication bypass: an attacker does not need a password to slip past the login gate, reach admin-level functions, and, in Hanley’s demonstration, turn that access into remote code execution on the server. That makes an exposed HFS instance more than a file share; it is a direct path to server control.

For operators running HFS on the internet, the exposure does not wait for a slower patch cycle. Once a bypass is public and already under attack, the remaining risk is every instance that still accepts traffic before v3.2.1 or later is in place.

1 source · 5h ago

CVE-2026-61500

NVD KEV

CVSS 9.8 CRITICAL: rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random()… EPSS 0.9% (57th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-10-03

Every edition of this story: Rejetto HFS Auth Bypass Hit Within a Day

More from today