Attackers are actively scanning for a Rejetto HFS (HTTP File Server) weakness, CVE-2026-61500, patched in version 3.2.1 and published on the NVD on 13 July 2026. The flaw is a session-cookie signing weakness and leakage issue: versions 3.0.0 through 3.2.0 derive their session-cookie signing key from the non-cryptographic Math.random() generator and disclose the generator's outputs to unauthenticated clients during login, so a remote attacker can collect a small number of login responses, reconstruct the generator state, recover the signing key and forge a valid administrator session cookie — leading to full administrative access and remote code execution via the server_code configuration feature. VulnCheck's Canary Intelligence honeypots observed probing activity over the weekend targeting CVE-2026-61500, described as small-scale reconnaissance from a single China Telecom IP address scanning deployments in Japan and the United States; Horizon3 researchers disclosed the finding on 30 September, and note its discovery used Anthropic's Mythos model to chain the weak PRNG with the output leak. Why it matters: an actively scanned, self-hosted file-server RCE with a readily available proof-of-concept puts CVE-2026-61500 squarely in patch-now territory for anyone running HFS 3.0.0–3.2.0.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-06 |
| Source | BleepingComputer |
| Reliability | Tier 2 |
| CVEs | CVE-2026-61500 |