Vulnerabilities · 2h ago

Rejetto HFS Cookie Forgery Opens Remote Code Execution

VulnCheck said Rejetto HTTP File Server (HFS) CVE-2026-61500 is seeing exploitation attempts after a public Python proof of concept showed how to forge administrator sessions on HFS 3.0.0 through 3.2.0. The flaw was already patched in 3.2.1, but the new code lowered the barrier from lab finding to workable attack.

The bug sits in how HFS makes and reveals login state: it derives the session-signing key from JavaScript Math.random() and leaks outputs from that same generator during login. With a few observed responses, an attacker can reconstruct the generator’s state, recover the key, mint a valid admin cookie, and then use the server_code feature to run server-side JavaScript.

That leaves exposed HFS instances with a trust problem, not just a version problem: if an attacker can see the login exchange, they may be able to impersonate admin before any obvious malware or brute-force signs appear. For internet-facing deployments, the practical exposure is forged administration followed by code execution, not a simple login bypass.

CVE-2026-61500

NVD KEV

CVSS 9.8 CRITICAL: rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random()… EPSS 1.0% (61st percentile).

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-10-05

Editions

Related stories