Executive Summary
In October 2026, security researchers detected active scanning campaigns targeting CVE-2026-61500, a critical remote code execution vulnerability in Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0. The flaw stems from weak session-cookie signing using non-cryptographic Math.random() generation and information leakage during login processes. Attackers can collect login responses, reconstruct the generator state, recover signing keys, and forge administrator session cookies to achieve full system access and remote code execution. VulnCheck's honeypots observed reconnaissance activity from China Telecom IP addresses targeting deployments in Japan and the United States.
This incident highlights the growing sophistication of AI-assisted vulnerability discovery and the rapid weaponization of technical proofs-of-concept. The vulnerability was originally discovered using Anthropic's Mythos model, demonstrating how AI is accelerating both defensive research and offensive exploitation timelines in cybersecurity.
Why This Matters Now
The active exploitation of CVE-2026-61500 represents a critical shift toward AI-accelerated vulnerability discovery and weaponization, with attackers rapidly targeting file-sharing infrastructure that often lacks proper security monitoring and patch management processes.
Attack Path Analysis
Attackers exploited CVE-2026-61500 in Rejetto HFS servers by reconstructing weak session signing keys through Math.random() output analysis, leading to administrator session forgery and remote code execution via server-side JavaScript execution capabilities. Following initial compromise, attackers could escalate privileges within the server environment, move laterally to internal systems, establish persistent command channels, exfiltrate sensitive files, and potentially deploy ransomware or destructive payloads.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers scanned for vulnerable Rejetto HFS servers (versions 3.0.0-3.2.0) and exploited CVE-2026-61500 by collecting login responses to reconstruct Math.random() generator state and recover session signing keys, forging valid administrator cookies
Related CVEs
CVE-2024-23692
CVSS 9.8Session-cookie signing weakness in Rejetto HFS allows remote attackers to forge administrator session cookies and achieve remote code execution via weak PRNG and information leakage.
Affected Products:
Rejetto HTTP File Server (HFS) – 3.0.0 through 3.2.0
Exploit Status:
active scanning observed
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter: JavaScript
Valid Accounts
Data Manipulation: Stored Data Manipulation
Domain Trust Discovery
Server Software Component: Web Shell
File and Directory Discovery
Exploitation of Remote Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Vulnerability Management
Control ID: 500.08
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Asset Management
Control ID: Identity: ID.AM-2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical RCE vulnerability in Rejetto HFS file servers enables session forgery and administrative takeover, threatening IT infrastructure and requiring immediate patching to version 3.2.1.
Financial Services
Session cookie manipulation and remote code execution risks compromise sensitive financial data sharing systems, violating regulatory compliance and enabling unauthorized access to confidential information.
Health Care / Life Sciences
HFS server vulnerabilities expose patient data sharing platforms to administrative takeover and malware installation, creating HIPAA compliance violations and patient privacy breaches.
Government Administration
Weak cryptographic implementations in file sharing infrastructure enable foreign adversaries to compromise government systems, steal classified data, and establish persistent administrative access.
Sources
- Rejetto HFS servers now actively scanned for critical RCE flawhttps://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/Verified
- CVE-2024-23692 Detail - NVDhttps://nvd.nist.gov/vuln/detail/CVE-2024-23692Verified
- Session forgery and RCE in Rejetto HFS - GitHub Security Advisoryhttps://github.com/rejetto/hfs/security/advisories/GHSA-3668-q9fx-9mxrVerified
- Horizon3 Attack Research - Rejetto HFS RCE Disclosurehttps://horizon3.ai/attack-research/disclosures/rejetto-hfs-rce-cve-2024-23692/Verified
- VulnCheck Intelligence - Active Scanning of Rejetto HFS Vulnerabilityhttps://vulncheck.com/blog/rejetto-hfs-scanningVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would be relevant to this CVE-2026-61500 incident by constraining lateral movement and reducing blast radius through network segmentation and controlled egress policies. The attacker's ability to pivot from the compromised HFS server to internal systems would likely be significantly limited.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial compromise of the HFS server would likely still occur, but the attacker's subsequent network discovery and reconnaissance activities would be constrained by segmented network visibility.
Control: Zero Trust Segmentation
Mitigation: While privilege escalation on the HFS server may still succeed, the attacker's ability to leverage those elevated privileges for broader network access would likely be constrained through workload isolation boundaries.
Control: East-West Traffic Security
Mitigation: Lateral movement attempts from the compromised server would likely be significantly constrained, reducing the attacker's ability to reach critical internal systems and limiting the overall blast radius.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely be constrained through network visibility monitoring that could detect and limit unauthorized external communication patterns from the compromised server.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be constrained through controlled egress policies that limit which external destinations the compromised server could transmit data to and monitor unusual data transfer patterns.
While local file system impacts on the HFS server may still occur, the scope of broader network disruption would likely be significantly reduced due to constrained lateral access and limited pivot capabilities.
Impact at a Glance
Affected Business Functions
- File Sharing Services
- Web Server Operations
- Remote Access Systems
- Document Management
Estimated downtime: 2 days
Estimated loss: N/A
Potential unauthorized access to all files hosted on HFS servers, including sensitive documents, proprietary data, and personal information depending on server usage. Complete administrative access could lead to data theft, modification, or deletion.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Inline IPS with CVE-2026-61500 signatures to detect and block exploit attempts targeting vulnerable Rejetto HFS servers before remote code execution occurs
- • Implement Zero Trust Segmentation to isolate file servers and prevent lateral movement from compromised systems to critical internal resources
- • Enable Egress Security & Policy Enforcement to detect and block unauthorized outbound connections from file servers that could indicate command and control or data exfiltration
- • Deploy Multicloud Visibility & Control to monitor for anomalous authentication patterns and repeated malformed requests indicating reconnaissance or exploitation attempts
- • Establish Cloud Native Security Fabric controls with real-time inspection capabilities to identify and respond to session forgery attacks and unauthorized administrative access attempts



