Security1 publisher1 min readPublished
Attackers scan Rejetto HFS servers for a signing-key flaw that grants admin control
VulnCheck says attackers are probing internet-facing Rejetto HFS servers for CVE-2026-61500, a signing-key flaw that gives full administrative control. The bug affects HFS 3.0.0 through 3.2.0, and the fix shipped in 3.2.1.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- The probes trace to a single China Telecom IP address aimed at HFS deployments in Japan and the United States, in what VulnCheck called small-scale reconnaissance.
- Horizon3 found the flaw using Anthropic's Mythos model, which flagged both the insecure signing-key generation and the login-time leak that made key recovery possible.
- VulnCheck has not reported any successful exploitation or post-exploitation activity, only the reconnaissance probes.
- Rejetto's current stable release is 3.3.4, which VulnCheck recommends installing as soon as possible.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A forged admin session exposes the server's stored files and any internal systems the HFS host can reach, turning one file server into a route inward.
- capability The attack is unauthenticated, so any internet-facing HFS server is reachable without a stolen or guessed password.
- decision A public proof-of-concept against unauthenticated code execution leaves exposed operators choosing between patching and taking the server offline.
- precedent An AI model surfaced a production code-execution chain, a sign automated tooling is now finding multi-step bugs, not just isolated flaws.
The chain starts with a weak key. HFS, Rejetto's free and open-source server for self-hosted file sharing on Windows, Linux and macOS, derives its session-cookie signing key from Math.random(), a non-cryptographic generator, and leaks that same generator's outputs to unauthenticated clients during login, according to the NIST NVD entry. [4][6] An attacker collects a small number of login responses, reconstructs the generator's internal state, recovers the signing key, and forges a valid administrator session cookie. [7] Math.random is predictable once enough of its output is observed, and the login responses supply exactly that. [6] From there the attacker reaches server_code, a built-in HFS feature that runs custom server-side JavaScript, and the forged session becomes remote code execution on the host. [11]
Horizon3's write-up and proof-of-concept arrived on September 30, 2026, 79 days after the CVE was published on July 13. [9][5][15] The release of those technical details is the likely trigger for the probing. [16] Horizon3 said its Mythos model "simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible." [10]
VulnCheck's Canary Intelligence honeypots caught the probing. Caitlin Condon, the firm's VP of security research, posted the finding on LinkedIn over the weekend. [2]
What to watch
- Whether VulnCheck or others report actual exploitation and post-compromise activity, not just scanning.
- Whether the probing broadens beyond the single China Telecom IP to more sources or regions.
- How many HFS 3.0.0 through 3.2.0 servers remain exposed and unpatched as the fix propagates.