Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Seatrium picks up 9th FSRU conversion job with Karpowership

    October 5, 2026

    Did Russian oligarch close to Putin fund part of Donald Trump Jr.’s wedding?

    October 5, 2026

    Accept ‘bad things’ in return for benefits of AI, says Sam Altman | OpenAI

    October 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Seatrium picks up 9th FSRU conversion job with Karpowership
    • Did Russian oligarch close to Putin fund part of Donald Trump Jr.’s wedding?
    • Accept ‘bad things’ in return for benefits of AI, says Sam Altman | OpenAI
    • The Interview – Olara Otunnu, diplomat: UN cannot be diplomatic ivory tower
    • Best Power Banks (2026): My Picks After Testing Over 100
    • Exploitation Hits Rejetto HFS Vulnerability Discovered by AI 
    • US payroll revision turns July job gain into a loss
    • ‘There could be local extinction’: The fight to protect Indonesia’s orangutans as El Niño fuels fires
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, October 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 5, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananOct 05, 2026Vulnerability / Web Security

    A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.

    The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and seize control of affected systems.

    “Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login,” according to an advisory for the flaw.

    “A remote attacker can collect a small number of login responses, reconstruct the generator’s state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature.”

    Horizon3.ai researcher Zach Hanley, in a post published on September 30, 2026, said Anthropic’s Mythos model was used to discover the vulnerability, describing it as an authentication bypass that facilitates arbitrary remote code execution on Rejetto HFS.

    “Rejetto HFS’s administrative API allows for custom endpoints that can execute arbitrary JavaScript,” Hanley said. “Combined, this presented a clear path from unauthenticated access to administrative control, and ultimately, remote code execution.”

    Cybersecurity

    A patch for the vulnerability was released in July 2026 in version 3.2.1. However, it was not until late September that a Python-based proof-of-concept (PoC) exploit was publicly released by a security researcher named Alejandro Ramos (aka aramosf).

    “HFS generated its Koa session-cookie signing key with JavaScript Math.random() and exposed outputs from the same V8 PRNG in the unauthenticated SRP login handshake,” Ramos noted. “An attacker can reconstruct the PRNG state, recover the signing key, forge an administrator session, and use the documented server_code configuration feature to execute server-side JavaScript.”

    According to VulnCheck’s Patrick Garrity, exploitation attempts were detected on October 1, 2026, a day after Horizon3.ai published additional details of the flaw. The cybersecurity company said it identified an unnamed threat actor in China targeting real vulnerable hosts in the U.S.

    CVE-2026-61500 is the second vulnerability in Rejetto HTTP File Server after CVE-2024-23692 (CVSS score: 9.8) to come under active exploitation in the wild. In July 2024, multiple threat actors were observed weaponizing the flaw to deliver cryptocurrency miners, trojans, and a malware named HATVIBE.

    Admin Attackers enables Flaw Forgery HFS RCE Rejetto Session Target
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Exploitation Hits Rejetto HFS Vulnerability Discovered by AI 

    Google halts open-source bug bounty program amid AI spam surge

    Alleged ShinyHunters Leader Arrested in Jordan

    Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

    A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data

    Citrix patches NetScaler SAML zero-day exploited in attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Seatrium picks up 9th FSRU conversion job with Karpowership

    October 5, 2026

    Did Russian oligarch close to Putin fund part of Donald Trump Jr.’s wedding?

    October 5, 2026

    Accept ‘bad things’ in return for benefits of AI, says Sam Altman | OpenAI

    October 5, 2026

    The Interview – Olara Otunnu, diplomat: UN cannot be diplomatic ivory tower

    October 5, 2026
    Latest Posts

    Bald Range Wildfire Forces Evacuation of 18,000 in British Columbia

    August 9, 2026

    Amazon deforestation alerts fall to lowest level since 2013, Brazilian data show

    August 9, 2026

    Institutional bear market: Why Bitcoin’s downturn is different

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Seatrium picks up 9th FSRU conversion job with Karpowership

    October 5, 2026

    Did Russian oligarch close to Putin fund part of Donald Trump Jr.’s wedding?

    October 5, 2026

    Accept ‘bad things’ in return for benefits of AI, says Sam Altman | OpenAI

    October 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.