Fast Facts
- Attackers are exploiting CVE-2026-61500 in Rejetto HTTP File Server by reconstructing predictable session signing keys from weak pseudo-random number generators, leading to full administrative access and remote code execution.
- The vulnerability enables remote attackers to forge valid admin session cookies, bypass authentication, and execute arbitrary JavaScript on the server, escalating to system control.
- Active exploitation has been detected targeting vulnerable U.S. hosts, with threat actors using this flaw to deploy malware, including cryptocurrency miners and trojans, increasing the risk of widespread compromise.
Threat Overview, Techniques, and Targets
A significant security flaw in Rejetto HTTP File Server (HFS) is currently being exploited. This flaw is identified as CVE-2026-61500 and has a high CVSS score of 9.3. Attackers use this vulnerability to forge admin sessions and gain full control over affected systems. The attack works because HFS versions 3.0.0 to 3.2.0 generate session cookies with a weak pseudo-random number generator. This generator leaks information that attackers can use to predict session keys.
The attackers collect login responses and reconstruct the cipher’s internal state. They then recover the signing key and forge valid administrator session cookies. Once they have admin access, attackers can use the server’s API to execute arbitrary JavaScript. This process allows attackers to perform remote code execution (RCE) on the server through the server_code feature.
The vulnerability has been exploited in real-world attacks. A threat actor in China was seen targeting U.S. systems shortly after details of the flaw became public. Previous similar vulnerabilities in HFS have also been exploited to deliver malware and cryptocurrencies.
Impact, Security Implications, and Remediation Guidance
The exploitation of this flaw can cause serious harm. Attackers who succeed can take over servers, run malicious code, and control affected systems remotely. This can lead to data theft, system damage, or use of the server to launch further attacks. Since the vulnerability allows for remote code execution, the threat to network security and data integrity is high.
Because a patch was released in July 2026 (version 3.2.1), it is strongly advised to update to this version. If you are using an older version of Rejetto HFS, you should upgrade immediately to prevent exploitation. For detailed remediation steps, it is recommended to consult the official vendor or follow related security advisories. Valid security practices include applying patches promptly and reviewing server configurations to ensure they are up-to-date.
Expand Your Tech Knowledge
Explore the future of technology with our detailed insights on Artificial Intelligence.
Discover archived knowledge and digital history on the Internet Archive.
ThreatIntel-V1
