Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Rejetto HFS Vulnerability Exploited for Admin Access

Rejetto HFS Vulnerability Exploited for Admin Access

Posted on October 5, 2026 By CWS

The Rejetto HTTP File Server (HFS) is currently facing active exploitation attempts due to a significant security vulnerability, as reported by VulnCheck. This flaw, identified as CVE-2026-61500 with a CVSS score of 9.3, arises from an inadequate pseudo-random number generator (PRNG), which results in a predictable session key. This vulnerability permits attackers to gain unauthorized access and potentially control affected systems.

Understanding the Vulnerability

Spanning versions 3.0.0 through 3.2.0 of Rejetto HFS, the vulnerability involves the derivation of a session-cookie signing key from the non-cryptographic Math.random() function. The system inadvertently reveals outputs from this generator to unauthenticated users during the login process. This flaw allows a remote threat actor to intercept login responses, recreate the generator’s state, retrieve the signing key, and forge a valid administrator session cookie. Consequently, this leads to complete administrative access and the ability to execute arbitrary remote code via the server’s code configuration feature.

Exploitation and Detection

On September 30, 2026, researcher Zach Hanley from Horizon3.ai elucidated on the vulnerability, discovered using Anthropic’s Mythos model. Hanley outlined the flaw as enabling an authentication bypass, which facilitates remote code execution on Rejetto HFS. The administrative API of HFS supports custom endpoints capable of executing arbitrary JavaScript, presenting a clear path from unauthorized access to administrative control and remote code execution.

Although a patch was introduced in July 2026 with version 3.2.1, public disclosure of a Python-based proof-of-concept (PoC) exploit by Alejandro Ramos followed in late September. Ramos highlighted that HFS’s use of the Math.random() function in generating Koa session-cookie signing keys, combined with the exposure during SRP login, allows attackers to reconstruct the PRNG state, forge session cookies, and execute server-side JavaScript.

Current Exploitation Efforts

VulnCheck’s Patrick Garrity reported exploitation attempts detected on October 1, 2026, shortly after Horizon3.ai released further details. The cybersecurity firm identified a threat actor based in China targeting vulnerable servers in the United States. This vulnerability marks the second active exploitation event involving Rejetto HFS, following CVE-2024-23692, which was exploited to deliver malicious payloads such as cryptocurrency miners and malware in mid-2024.

As security threats continue to evolve, addressing such vulnerabilities is critical for safeguarding systems against unauthorized access and potential cyberattacks. Staying informed and applying necessary patches promptly can mitigate risks associated with these exploits.

The Hacker News Tags:authentication bypass, CVE-2026-61500, Cybersecurity, Exploit, PRNG, Rejetto HFS, remote code execution, session forgery, system security, Vulnerability

Post navigation

Previous Post: Leading Authorization Tools of 2026: Top 10 Revealed
Next Post: Google AI Tool Uncovers 500+ XSS Vulnerabilities

Related Posts

Critical NGINX Bug Poses Remote Code Execution Risk Critical NGINX Bug Poses Remote Code Execution Risk The Hacker News
Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months The Hacker News
GitLab Vulnerability Faces Quick Exploitation GitLab Vulnerability Faces Quick Exploitation The Hacker News
Ex-Google Engineer Convicted for Stealing 2,000 AI Trade Secrets for China Startup Ex-Google Engineer Convicted for Stealing 2,000 AI Trade Secrets for China Startup The Hacker News
MikroTrick Exploit Grants Router Control Without Authentication MikroTrick Exploit Grants Router Control Without Authentication The Hacker News
Phishing Attack Evades Detection Using Fake Teams Update Phishing Attack Evades Detection Using Fake Teams Update The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google AI Tool Uncovers 500+ XSS Vulnerabilities
  • Rejetto HFS Vulnerability Exploited for Admin Access
  • Leading Authorization Tools of 2026: Top 10 Revealed
  • Citrix Patches Critical NetScaler Vulnerability Exploited in Attacks
  • Alleged Cybercrime Leader Arrested in Jordan

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google AI Tool Uncovers 500+ XSS Vulnerabilities
  • Rejetto HFS Vulnerability Exploited for Admin Access
  • Leading Authorization Tools of 2026: Top 10 Revealed
  • Citrix Patches Critical NetScaler Vulnerability Exploited in Attacks
  • Alleged Cybercrime Leader Arrested in Jordan

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark