Critical Rejetto HFS Vulnerability Exploited in the Wild, Researchers Warn
Security monitoring firm VulnCheck has confirmed that attackers are actively probing for and exploiting a high‑severity flaw in Rejetto HTTP File Server, identified as CVE-2026-61500. The vulnerability carries a CVSS rating of 9.3, placing it in the critical range and signaling a strong likelihood of remote code execution when successfully leveraged.
Rejetto HTTP File Server, commonly referred to as HFS, is a lightweight web‑based file‑sharing application that runs on Windows platforms. Its ease of deployment and minimal configuration requirements have made it popular with small businesses, hobbyist developers, and internal IT teams that need a quick way to host files without a full‑blown web server.
The root cause of CVE-2026-61500 is a weak pseudo‑random number generator used to produce session identifiers for authenticated users. Because the generated tokens lack sufficient entropy, an attacker who can observe or guess a token can forge an administrator session. Once an admin session is impersonated, the attacker can inject commands that the server executes with the same privileges, effectively achieving remote code execution.
VulnCheck’s telemetry shows a noticeable uptick in scans targeting the specific URL patterns associated with the vulnerable HFS installation. The firm reports that several of these probes appear to be coupled with payload delivery attempts, indicating that exploitation is moving beyond proof‑of‑concept into active campaigns.
Successful exploitation gives a malicious actor complete control over the compromised host. In practice, this could lead to data exfiltration, deployment of ransomware, or the server being enlisted in larger botnet operations. Organizations still running legacy versions of HFS are especially exposed, as the flaw exists in releases that have not received recent security updates.
The developers of HFS have issued an advisory urging users to upgrade to the latest release, which incorporates a stronger random‑number generator and additional session hardening measures. Administrators are also advised to restrict access to the HFS management interface, enforce network‑level firewalls, and monitor authentication logs for anomalous activity. For environments where immediate patching is not feasible, disabling remote administration features and employing a reverse proxy with strict access controls can mitigate risk.
Security analysts expect that exploitation attempts will continue to rise until the vulnerable software is broadly updated. Organizations are encouraged to conduct an inventory of all HFS deployments, assess their exposure, and prioritize remediation. The episode underscores the broader challenge of maintaining up‑to‑date components in low‑cost, widely distributed utilities that often escape the rigorous patch management processes applied to larger enterprise systems.
Comments (0)
Be the first to comment.
Join the discussion