Security2 publishers2 min readPublished
China-based actor targets U.S. Rejetto HFS servers through a forgeable admin cookie
VulnCheck says a China-based actor began targeting vulnerable U.S. Rejetto HFS servers on October 1, exploiting CVE-2026-61500 to forge admin sessions. The fix shipped in July as version 3.2.1. Exposed instances that have not updated are reachable now.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- HFS versions 3.0.0 through 3.2.0 derive the session-cookie signing key from the non-cryptographic Math.random() and hand outputs of the same generator to unauthenticated clients during login.
- The session-forgery flaw, tracked as CVE-2026-61500, carries a CVSS score of 9.3.
- A Python proof-of-concept from a researcher known as aramosf, Alejandro Ramos, went public in late September 2026.
- It is the second HFS flaw to come under active exploitation, after CVE-2024-23692, which was rated 9.8.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Any internet-facing HFS on the affected builds is exploitable by a remote attacker with no credentials, ending in code execution on the host.
- decision The 3.2.1 fix has been out since July, so for exposed hosts the choice now is to update off the normal patch cycle or take them offline.
- precedent With working exploit code public, opportunistic scanning for vulnerable HFS hosts is the expected next move.
The fix has been available for roughly three months [1]. Horizon3.ai researcher Zach Hanley published an analysis on September 30, 2026, and said Anthropic's Mythos model was used to find the flaw, which he described as an authentication bypass that enables arbitrary remote code execution [5]. Patrick Garrity of VulnCheck said the attempts came one day after Horizon3.ai published additional details [11].
The advisory for the flaw lays out the chain: "A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature." [4]
Alejandro Ramos, who published the proof-of-concept, described the same path in the browser engine's terms. "HFS generated its Koa session-cookie signing key with JavaScript Math.random() and exposed outputs from the same V8 PRNG in the unauthenticated SRP login handshake," he wrote [10].
Hanley traced how admin access turns into code execution. "Rejetto HFS's administrative API allows for custom endpoints that can execute arbitrary JavaScript," he said [6]. "Combined, this presented a clear path from unauthenticated access to administrative control, and ultimately, remote code execution." [7]
HFS has drawn attackers before. In July 2024, multiple threat actors weaponized CVE-2024-23692 to deliver cryptocurrency miners, trojans, and a malware named HATVIBE [14].
What to watch
- Whether the China-based activity broadens into mass scanning now that a working proof-of-concept is public.
- Whether other actors adopt CVE-2026-61500 to drop miners or malware, as happened with CVE-2024-23692 in 2024.
- Whether trackers report compromise of hosts that stayed on 3.0.0 through 3.2.0 after the July fix.