CVE-2026-61500
CVSS 9.8 CRITICAL: rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random()… EPSS 1.0% (61st percentile).
Vulnerabilities · 2h ago
VulnCheck said Rejetto HTTP File Server (HFS) CVE-2026-61500 is seeing exploitation attempts after a public Python proof of concept showed how to forge administrator sessions on HFS 3.0.0 through 3.2.0. The flaw was already patched in 3.2.1, but the new code lowered the barrier from lab finding to workable attack.
The bug sits in how HFS makes and reveals login state: it derives the session-signing key from JavaScript Math.random() and leaks outputs from that same generator during login. With a few observed responses, an attacker can reconstruct the generator’s state, recover the key, mint a valid admin cookie, and then use the server_code feature to run server-side JavaScript.
That leaves exposed HFS instances with a trust problem, not just a version problem: if an attacker can see the login exchange, they may be able to impersonate admin before any obvious malware or brute-force signs appear. For internet-facing deployments, the practical exposure is forged administration followed by code execution, not a simple login bypass.
CVSS 9.8 CRITICAL: rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random()… EPSS 1.0% (61st percentile).
3 sources covering this story
Exploitation Hits Rejetto HFS Vulnerability Discovered by AI
CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE.
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Rejetto HFS CVE-2026-61500 faces exploitation attempts after a public PoC showed forged admin sessions can lead to remote code execution.
Exploitation attempts came from China-hosted IP, VulnCheck researcher says
Part of the PlainSec briefing for 2026-10-05