CVE-2026-61500: How to Detect & Patch Rejetto HFS RCE Flaw

SOC Briefing Summary :: Executive Key Takeaways
- [01]Critical authentication bypass and RCE vulnerability (CVE-2026-61500, CVSS 9.3) in Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0 is under active internet-wide scanning.
- [02]Root cause stems from generating session-cookie signing keys with JavaScript's non-cryptographic Math.random(), enabling state recovery from unauthenticated SRP handshakes.
- [03]System administrators must upgrade exposed Rejetto HFS instances to version 3.2.1 immediately and restart services to invalidate forged administrator sessions.
Executive Summary
Threat actors and automated botnets have begun actively scanning the public internet for exposed Rejetto HTTP File Server (HFS) deployments vulnerable to a critical security flaw tracked as CVE-2026-61500. Carrying a CVSS v3 score of 9.3, the vulnerability enables unauthenticated remote adversaries to bypass authentication, forge administrative session credentials, and execute arbitrary operating system commands on hosting servers.
Rejetto HFS version 3—a modern rewrite of the popular open-source file-sharing utility built on Node.js—is widely deployed by organizations, homelabs, and IT teams for lightweight internal and cross-boundary file transfers. The flaw stems from an insecure pseudo-random number generator (PRNG) implementation in the server's session-signing infrastructure, which leaks sufficient internal state during unauthenticated login handshakes to allow complete key reconstruction.
With public proof-of-concept (PoC) exploit scripts circulating and mass scanning underway across public IPv4 subnets, security teams must immediately identify all exposed HFS endpoints and apply the vendor security update to HFS version 3.2.1.
---
Technical Vulnerability Analysis & Attack Chain

Root-Cause & Exploitation Mechanics
The root cause of CVE-2026-61500 lies in Rejetto HFS v3's failure to utilize a cryptographically secure random number generator (CSPRNG) when initializing its session management subsystem.
- Non-Cryptographic PRNG Key Derivation: When the HFS server process boots, it generates a secret signing key used to cryptographically sign session cookies (JWTs/tokens). Rather than invoking Node.js's native
crypto.randomBytes(), the application calledMath.random(). In Google V8 runtime engines,Math.random()relies on the deterministic xorshift128+ PRNG algorithm, which maintains only 128 bits of internal state. - PRNG State Leakage via SRP Handshake: To support zero-knowledge authentication, HFS implements the Secure Remote Password (SRP) protocol. During the initial, unauthenticated phase of the SRP handshake on the
/~/api/endpoint, the server transmits pseudo-random challenge values that are also generated viaMath.random(). - State Inversion & Key Recovery: Because xorshift128+ is not cryptographically secure, an external observer collecting a sequence of consecutive floating-point numbers from the SRP handshake can solve a system of linear equations over GF(2) and recover the complete 128-bit internal seed state of the V8 PRNG. By stepping the generator backward, the attacker reconstructs the exact secret string generated at server startup.
- Admin Cookie Forgery to RCE: Armed with the recovered secret key, the adversary creates an arbitrary session cookie populated with
{ "username": "admin", "admin": true }and signs it. When submitted in HTTP request headers, the HFS server validates the forged signature. The attacker then accesses the administrative configuration API and abuses the legitimateserver_codefeature—a mechanism designed to let administrators execute server-side Node.js plugins—to spawn arbitrary operating system shells (child_process.exec).
---
MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)
| Tactic | Technique ID | Technique Name | Operational Context |
|---|---|---|---|
| Reconnaissance | T1595.002 | Active Scanning: Vulnerability Scanning | Probing exposed Rejetto HFS web endpoints across public IPv4 ranges |
| Initial Access | T1190 | Exploit Public-Facing Application | Exploiting weak session signing keys in Rejetto HFS API |
| Defense Evasion | T1556.006 | Modify Authentication Process: Session Hijacking | Forging valid administrative session cookies via PRNG inversion |
| Execution | T1059.007 | Command and Scripting Interpreter: JavaScript | Executing Node.js commands via the HFS server_code configuration parameter |
| Execution | T1059.003 | Windows Command Shell | Spawning cmd.exe or PowerShell child processes from hfs.exe |
---
Threat Actor Profile & Campaign Attribution
The vulnerability was initially uncovered by security researchers participating in Project Glasswing utilizing advanced AI-assisted static and symbolic code analysis. However, following public disclosure, opportunistic threat actors and cryptocurrency mining botnets quickly weaponized the finding.
Telemetry indicates automated scanning clusters originating from bulletproof hosting providers, systematically sweeping TCP ports 80, 443, 8080, and 8888 for Rejetto HFS HTTP response headers (Server: HFS). Once admin session forgery is achieved, observed exploit payloads attempt to stage automated shell scripts, drop XMRig miners, or install persistent Web shells on the hosting server.
---
Detection & SOC Mitigation Playbook
1. Concrete Remediation & Workarounds
Organizations operating Rejetto HTTP File Server must execute the following remediation steps immediately:
- Upgrade Rejetto HFS to Version 3.2.1:
Download and deploy HFS release 3.2.1 or later, which replaces Math.random() with crypto.randomBytes() for all cryptographic operations:
# If running via npm / Node.js:
npm install -g hfs@latest
# Or replace binary directly from the official Rejetto repository- Invalidate Active Sessions & Rotate Secrets:
Completely stop and restart the HFS service to purge in-memory session caches and force the generation of a new cryptographically secure session signing key.
- Isolate Server from Public Internet:
Place the Rejetto HFS management interface behind an authenticated reverse proxy (e.g., Cloudflare Access, Nginx with mTLS, or enterprise VPN) and restrict direct access to trusted internal IP ranges:
# Windows Defender Firewall rule restricting HFS port 8080 to internal subnets
netsh advfirewall firewall add rule name="Restrict Rejetto HFS" dir=in action=allow protocol=TCP localport=8080 remoteip=192.168.1.0/24,10.0.0.0/8- Audit server_code Configurations:
Inspect the HFS configuration file (config.yaml or options.json) to verify that no unauthorized scripts have been appended to the server_code parameter.
2. Network & Perimeter Defenses
- WAF Inspection: Implement rules inspecting inbound requests targeting
/~/api/endpoints. Flag or throttle clients generating high-volume, rapid-succession SRP handshake initialization requests from single IP addresses. - Header Stripping: Ensure reverse proxies strip unauthorized
Cookieheaders or sanitize cookie payloads that contain abnormal session claims without corresponding back-end session store mappings.
3. Endpoint Detection & Hunting Query
Sigma Rule: Rejetto HFS Process Spawning Command Shell
title: Rejetto HFS Spawning Interactive Shell Process
id: b83f1240-a102-45e8-b801-7fa85b1c9055
status: experimental
description: Detects Rejetto HFS or Node.js parent processes spawning system command interpreters, indicative of CVE-2026-61500 exploitation.
references:
- https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/
author: CyberNewsAI Threat Research Team
date: 2026-10-05
tags:
- attack.execution
- attack.t1059.003
- attack.t1059.007
logsource:
category: process_creation
product: windows
detection:
selection_parent:
Image|endswith:
- '\hfs.exe'
- '\node.exe'
CommandLine|contains:
- 'hfs'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
- '\curl.exe'
condition: selection_parent and selection_child
falsepositives:
- Legitimate custom administrative scripts intentionally configured by the system owner.
level: criticalMicrosoft Sentinel / Defender KQL Hunting Query
// Hunt for abnormal child process execution originating from Rejetto HFS binary or Node instance
DeviceProcessEvents
| where Timestamp > ago(7d)
| where InitiatingProcessFileName in~ ("hfs.exe", "node.exe")
| where InitiatingProcessCommandLine has "hfs" or InitiatingProcessFolderPath has_any ("hfs", "rejetto")
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "curl.exe", "certutil.exe", "whoami.exe", "sh", "bash")
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, AccountName
| order by Timestamp desc---
| Indicator Type | Value / Pattern | Context |
|---|---|---|
| CVE ID | CVE-2026-61500 | Critical Session Forgery & RCE in Rejetto HFS |
| Affected Versions | Rejetto HFS v3.0.0 through v3.2.0 | Vulnerable Node.js implementation with Math.random() PRNG |
| Fixed Version | Rejetto HFS v3.2.1 | Patched release with crypto.randomBytes() |
| Exploited URI Path | /~/api/ | Secure Remote Password endpoint abused for PRNG state leakage |
| Suspicious Child Process | hfs.exe -> cmd.exe /c or powershell.exe | Artifact of malicious server_code execution |
CVE-2026-61500Rejetto HTTP File Server (HFS) v3.0.0 - v3.2.0Rejetto HFS v3.2.1/~/api/ (Secure Remote Password Handshake)server_code configuration parameter// VERIFIED_SOURCES_&_REFERENCES
Watch Full Video Briefings on YouTube
Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.
Related Threat Intelligence
View Archive
Warlock Ransomware Hits Water and Telecom via SharePoint Flaws
China-linked Warlock ransomware breaches water and telecom operators via SharePoint flaws, deploying BYOVD EDR-killers and VS Code tunnels to strike 40 hosts.

Antino Backdoor Abuses M365 Outlook & OneDrive for Covert C2
China-nexus threat actor UAT-11587 targets Asian government entities with the Rust-based Antino backdoor, abusing Microsoft 365 Outlook and OneDrive for C2.

GitLab AI Gateway Critical RCE Flaw Allows Remote Code Execution
GitLab patches a critical RCE flaw in its AI Gateway service enabling authenticated users to escape prompt sandboxes and run arbitrary code on hosting servers.