CVE-2026-61500: How to Detect & Patch Rejetto HFS RCE Flaw

•By CyberNewsAI Threat Research Team•VERIFIED INTEL
Rejetto HFS CVE-2026-61500 Weak Signing Key RCE Architecture and Telemetry Overview

SOC Briefing Summary :: Executive Key Takeaways

  • [01]Critical authentication bypass and RCE vulnerability (CVE-2026-61500, CVSS 9.3) in Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0 is under active internet-wide scanning.
  • [02]Root cause stems from generating session-cookie signing keys with JavaScript's non-cryptographic Math.random(), enabling state recovery from unauthenticated SRP handshakes.
  • [03]System administrators must upgrade exposed Rejetto HFS instances to version 3.2.1 immediately and restart services to invalidate forged administrator sessions.
SHARE INTEL:Reddit

Executive Summary

Threat actors and automated botnets have begun actively scanning the public internet for exposed Rejetto HTTP File Server (HFS) deployments vulnerable to a critical security flaw tracked as CVE-2026-61500. Carrying a CVSS v3 score of 9.3, the vulnerability enables unauthenticated remote adversaries to bypass authentication, forge administrative session credentials, and execute arbitrary operating system commands on hosting servers.

Rejetto HFS version 3—a modern rewrite of the popular open-source file-sharing utility built on Node.js—is widely deployed by organizations, homelabs, and IT teams for lightweight internal and cross-boundary file transfers. The flaw stems from an insecure pseudo-random number generator (PRNG) implementation in the server's session-signing infrastructure, which leaks sufficient internal state during unauthenticated login handshakes to allow complete key reconstruction.

With public proof-of-concept (PoC) exploit scripts circulating and mass scanning underway across public IPv4 subnets, security teams must immediately identify all exposed HFS endpoints and apply the vendor security update to HFS version 3.2.1.

---

Technical Vulnerability Analysis & Attack Chain

Attack Chain Flow
// Attack Chain Flow

Root-Cause & Exploitation Mechanics

The root cause of CVE-2026-61500 lies in Rejetto HFS v3's failure to utilize a cryptographically secure random number generator (CSPRNG) when initializing its session management subsystem.

  • Non-Cryptographic PRNG Key Derivation: When the HFS server process boots, it generates a secret signing key used to cryptographically sign session cookies (JWTs/tokens). Rather than invoking Node.js's native crypto.randomBytes(), the application called Math.random(). In Google V8 runtime engines, Math.random() relies on the deterministic xorshift128+ PRNG algorithm, which maintains only 128 bits of internal state.
  • PRNG State Leakage via SRP Handshake: To support zero-knowledge authentication, HFS implements the Secure Remote Password (SRP) protocol. During the initial, unauthenticated phase of the SRP handshake on the /~/api/ endpoint, the server transmits pseudo-random challenge values that are also generated via Math.random().
  • State Inversion & Key Recovery: Because xorshift128+ is not cryptographically secure, an external observer collecting a sequence of consecutive floating-point numbers from the SRP handshake can solve a system of linear equations over GF(2) and recover the complete 128-bit internal seed state of the V8 PRNG. By stepping the generator backward, the attacker reconstructs the exact secret string generated at server startup.
  • Admin Cookie Forgery to RCE: Armed with the recovered secret key, the adversary creates an arbitrary session cookie populated with { "username": "admin", "admin": true } and signs it. When submitted in HTTP request headers, the HFS server validates the forged signature. The attacker then accesses the administrative configuration API and abuses the legitimate server_code feature—a mechanism designed to let administrators execute server-side Node.js plugins—to spawn arbitrary operating system shells (child_process.exec).

---

MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)

MITRE ATT&CK • OPERATIONAL TTP MAPPING
TacticTechnique IDTechnique NameOperational Context
ReconnaissanceT1595.002Active Scanning: Vulnerability ScanningProbing exposed Rejetto HFS web endpoints across public IPv4 ranges
Initial AccessT1190Exploit Public-Facing ApplicationExploiting weak session signing keys in Rejetto HFS API
Defense EvasionT1556.006Modify Authentication Process: Session HijackingForging valid administrative session cookies via PRNG inversion
ExecutionT1059.007Command and Scripting Interpreter: JavaScriptExecuting Node.js commands via the HFS server_code configuration parameter
ExecutionT1059.003Windows Command ShellSpawning cmd.exe or PowerShell child processes from hfs.exe

---

Threat Actor Profile & Campaign Attribution

The vulnerability was initially uncovered by security researchers participating in Project Glasswing utilizing advanced AI-assisted static and symbolic code analysis. However, following public disclosure, opportunistic threat actors and cryptocurrency mining botnets quickly weaponized the finding.

Telemetry indicates automated scanning clusters originating from bulletproof hosting providers, systematically sweeping TCP ports 80, 443, 8080, and 8888 for Rejetto HFS HTTP response headers (Server: HFS). Once admin session forgery is achieved, observed exploit payloads attempt to stage automated shell scripts, drop XMRig miners, or install persistent Web shells on the hosting server.

---

Detection & SOC Mitigation Playbook

1. Concrete Remediation & Workarounds

Organizations operating Rejetto HTTP File Server must execute the following remediation steps immediately:

  1. Upgrade Rejetto HFS to Version 3.2.1:

Download and deploy HFS release 3.2.1 or later, which replaces Math.random() with crypto.randomBytes() for all cryptographic operations:

QUERY / DETECTION_RULE
BASH / CLI
# If running via npm / Node.js:
npm install -g hfs@latest
# Or replace binary directly from the official Rejetto repository
  1. Invalidate Active Sessions & Rotate Secrets:

Completely stop and restart the HFS service to purge in-memory session caches and force the generation of a new cryptographically secure session signing key.

  1. Isolate Server from Public Internet:

Place the Rejetto HFS management interface behind an authenticated reverse proxy (e.g., Cloudflare Access, Nginx with mTLS, or enterprise VPN) and restrict direct access to trusted internal IP ranges:

QUERY / DETECTION_RULE
BASH / CLI
# Windows Defender Firewall rule restricting HFS port 8080 to internal subnets
netsh advfirewall firewall add rule name="Restrict Rejetto HFS" dir=in action=allow protocol=TCP localport=8080 remoteip=192.168.1.0/24,10.0.0.0/8
  1. Audit server_code Configurations:

Inspect the HFS configuration file (config.yaml or options.json) to verify that no unauthorized scripts have been appended to the server_code parameter.

2. Network & Perimeter Defenses

  • WAF Inspection: Implement rules inspecting inbound requests targeting /~/api/ endpoints. Flag or throttle clients generating high-volume, rapid-succession SRP handshake initialization requests from single IP addresses.
  • Header Stripping: Ensure reverse proxies strip unauthorized Cookie headers or sanitize cookie payloads that contain abnormal session claims without corresponding back-end session store mappings.

3. Endpoint Detection & Hunting Query

Sigma Rule: Rejetto HFS Process Spawning Command Shell

QUERY / DETECTION_RULE
SIGMA / YAML
title: Rejetto HFS Spawning Interactive Shell Process
id: b83f1240-a102-45e8-b801-7fa85b1c9055
status: experimental
description: Detects Rejetto HFS or Node.js parent processes spawning system command interpreters, indicative of CVE-2026-61500 exploitation.
references:
  - https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/
author: CyberNewsAI Threat Research Team
date: 2026-10-05
tags:
  - attack.execution
  - attack.t1059.003
  - attack.t1059.007
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    Image|endswith:
      - '\hfs.exe'
      - '\node.exe'
    CommandLine|contains:
      - 'hfs'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\certutil.exe'
      - '\bitsadmin.exe'
      - '\curl.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Legitimate custom administrative scripts intentionally configured by the system owner.
level: critical

Microsoft Sentinel / Defender KQL Hunting Query

QUERY / DETECTION_RULE
SENTINEL / KQL
// Hunt for abnormal child process execution originating from Rejetto HFS binary or Node instance
DeviceProcessEvents
| where Timestamp > ago(7d)
| where InitiatingProcessFileName in~ ("hfs.exe", "node.exe")
| where InitiatingProcessCommandLine has "hfs" or InitiatingProcessFolderPath has_any ("hfs", "rejetto")
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "curl.exe", "certutil.exe", "whoami.exe", "sh", "bash")
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, AccountName
| order by Timestamp desc

---

Indicator TypeValue / PatternContext
CVE IDCVE-2026-61500Critical Session Forgery & RCE in Rejetto HFS
Affected VersionsRejetto HFS v3.0.0 through v3.2.0Vulnerable Node.js implementation with Math.random() PRNG
Fixed VersionRejetto HFS v3.2.1Patched release with crypto.randomBytes()
Exploited URI Path/~/api/Secure Remote Password endpoint abused for PRNG state leakage
Suspicious Child Processhfs.exe -> cmd.exe /c or powershell.exeArtifact of malicious server_code execution
Indicators of Compromise (IOCs)
5 Identified
VulnerabilityCVE-2026-61500
Affected SoftwareRejetto HTTP File Server (HFS) v3.0.0 - v3.2.0
Remediation ReleaseRejetto HFS v3.2.1
Target API Endpoint/~/api/ (Secure Remote Password Handshake)
Vulnerable Parameterserver_code configuration parameter
SHARE INTEL:Reddit
OPERATIONS_BROADCAST

Watch Full Video Briefings on YouTube

Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.

SUBSCRIBE_ON_YOUTUBE