Skip to content

Security1 publisher1 min readPublished

Attackers scan Rejetto HFS servers for a signing-key flaw that grants admin control

VulnCheck says attackers are probing internet-facing Rejetto HFS servers for CVE-2026-61500, a signing-key flaw that gives full administrative control. The bug affects HFS 3.0.0 through 3.2.0, and the fix shipped in 3.2.1.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • The probes trace to a single China Telecom IP address aimed at HFS deployments in Japan and the United States, in what VulnCheck called small-scale reconnaissance.
  • Horizon3 found the flaw using Anthropic's Mythos model, which flagged both the insecure signing-key generation and the login-time leak that made key recovery possible.
  • VulnCheck has not reported any successful exploitation or post-exploitation activity, only the reconnaissance probes.
  • Rejetto's current stable release is 3.3.4, which VulnCheck recommends installing as soon as possible.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A forged admin session exposes the server's stored files and any internal systems the HFS host can reach, turning one file server into a route inward.
  • capability The attack is unauthenticated, so any internet-facing HFS server is reachable without a stolen or guessed password.
  • decision A public proof-of-concept against unauthenticated code execution leaves exposed operators choosing between patching and taking the server offline.
  • precedent An AI model surfaced a production code-execution chain, a sign automated tooling is now finding multi-step bugs, not just isolated flaws.

The chain starts with a weak key. HFS, Rejetto's free and open-source server for self-hosted file sharing on Windows, Linux and macOS, derives its session-cookie signing key from Math.random(), a non-cryptographic generator, and leaks that same generator's outputs to unauthenticated clients during login, according to the NIST NVD entry. [4][6] An attacker collects a small number of login responses, reconstructs the generator's internal state, recovers the signing key, and forges a valid administrator session cookie. [7] Math.random is predictable once enough of its output is observed, and the login responses supply exactly that. [6] From there the attacker reaches server_code, a built-in HFS feature that runs custom server-side JavaScript, and the forged session becomes remote code execution on the host. [11]

Horizon3's write-up and proof-of-concept arrived on September 30, 2026, 79 days after the CVE was published on July 13. [9][5][15] The release of those technical details is the likely trigger for the probing. [16] Horizon3 said its Mythos model "simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible." [10]

VulnCheck's Canary Intelligence honeypots caught the probing. Caitlin Condon, the firm's VP of security research, posted the finding on LinkedIn over the weekend. [2]

What to watch

  • Whether VulnCheck or others report actual exploitation and post-compromise activity, not just scanning.
  • Whether the probing broadens beyond the single China Telecom IP to more sources or regions.
  • How many HFS 3.0.0 through 3.2.0 servers remain exposed and unpatched as the fix propagates.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories