Overview
Rejetto HFS servers are now being actively probed for a critical vulnerability that can turn an unauthenticated request into administrative access and ultimately remote code execution. Tracked as CVE-2026-61500, the flaw affects Rejetto HFS versions 3.0.0 through 3.2.0. The vulnerability was patched in version 3.2.1, but the release of a public proof-of-concept has now been followed by reconnaissance activity against exposed systems. The significance extends beyond another vulnerable file-sharing application. The vulnerability demonstrates how weaknesses in authentication design can become dramatically more serious when combined with information leakage and a privileged server-side execution capability.
The Authentication Boundary Was Predictable
HFS used JavaScript’s Math.random() to generate the signing material used to protect session cookies. That mechanism is designed for general-purpose randomness, not cryptographic security. The problem became significantly more serious because the application also exposed outputs from the same pseudo-random number generator through an unauthenticated login process. Researchers were therefore able to use those observations to reconstruct the generator’s state and recover the information required to forge a legitimate administrator session. The result is a fundamental authentication failure: the attacker does not need to steal an administrator’s password if the application can be persuaded to create a valid administrator session mathematically.
From Session Forgery to Remote Code Execution
Administrative access would already represent a serious compromise of a file-sharing server. In HFS, however, the impact can extend further because the platform includes functionality capable of executing server-side JavaScript. Researchers demonstrated a complete attack chain from unauthenticated interaction through session forgery and administrative access to remote code execution. That makes the vulnerability particularly dangerous for internet-facing HFS deployments. A compromised file server could expose shared data, allow files to be modified or deleted, provide a platform for malware deployment and potentially become a stepping stone into other internal systems. The issue also demonstrates why vulnerability severity cannot always be understood by examining one coding mistake in isolation. A weak random-number generator, an information leak and a privileged application feature may each appear manageable independently. Together, they can form a complete compromise path.
AI Is Changing the Economics of Vulnerability Research
The vulnerability was discovered by Horizon3 researchers using Anthropic’s Mythos model. The research demonstrated an important emerging capability: the model did not simply identify insecure random-number generation. It connected that weakness with another code path leaking values from the same random-number stream and recognised that the two weaknesses could be chained. That matters for defenders because the economics of exploit development are changing. Vulnerabilities that previously required specialist mathematical knowledge and significant research time may become easier to analyse and weaponise as AI-assisted security research improves. The subsequent appearance of probing activity shortly after the public technical disclosure reinforces another reality: the time between vulnerability disclosure and attacker reconnaissance continues to shrink.
Exposure Matters More Than the Size of the Deployment
Organisations running HFS should upgrade affected installations to 3.2.1 or later, with the latest stable release preferred. Internet-facing instances deserve the highest priority. Patch management should also be accompanied by exposure assessment. File-sharing servers are often deployed for a specific operational requirement and can remain online long after the original business need has changed. An obscure server that is rarely monitored can therefore become an attractive external entry point. Existing internet-facing systems running vulnerable versions should also be investigated for unexpected administrative activity, configuration changes, unfamiliar scripts and other indicators of compromise. Active scanning does not prove that a particular system was successfully compromised, but it does demonstrate that vulnerable systems are being discovered.
Expert in the Cloud Insight
CVE-2026-61500 reinforces a broader security principle: authentication is only as strong as the mechanism used to establish trust in the session. A system can have strong passwords, encrypted communications and conventional access controls, yet still fail if the cryptographic material protecting its sessions can be predicted. The growing use of AI in vulnerability discovery makes this even more important. Security weaknesses that once remained theoretical because exploitation was too complex may increasingly become practical attack paths. A vulnerability does not become dangerous when attackers discover the software; it becomes dangerous when the path from unauthenticated request to trusted execution becomes repeatable.
Leave a Reply