Back to Intelligence

CVE-2026-61500: Rejetto HFS Authentication Bypass and Unauthenticated RCE Actively Exploited — Detection and Remediation Guide

SA
Security Arsenal Team
October 5, 2026
11 min read

Rejetto HTTP File Server (HFS) — a lightweight, wildly popular utility used to share files over HTTP with minimal setup — has a critical vulnerability that is no longer theoretical. CVE-2026-61500 (CVSS 9.3) allows an unauthenticated remote attacker to bypass authentication and execute arbitrary code on the host running HFS. The flaw was discovered with the assistance of Anthropic's Mythos AI model during a security research effort, and threat actors have moved quickly: exploitation in the wild is confirmed.

This is the second time in recent memory that HFS has become an exploitation magnet, and the pattern should concern every defender. HFS is frequently deployed by individuals, small teams, and even enterprises as a quick-and-dirty file drop — often directly exposed to the internet, often running with elevated privileges, and almost never inventoried in an asset management system. That combination makes it exactly the kind of shadow-IT target that ransomware affiliates and initial access brokers scan for within hours of a public disclosure.

If HFS is running anywhere in your environment — sanctioned or not — treat this as an emergency patch event.

Technical Analysis

Affected Product

  • Product: Rejetto HTTP File Server (HFS)
  • Platforms: Primarily Windows (HFS runs as a standalone executable, hfs.exe, and is also deployed via Node.js for HFS 3.x on Linux and macOS)
  • CVE: CVE-2026-61500
  • CVSS: 9.3 (Critical)
  • Impact: Authentication bypass leading to unauthenticated remote code execution

How the Vulnerability Works

Based on the disclosure, CVE-2026-61500 chains two weaknesses in the HFS HTTP request-handling logic:

  1. Authentication bypass: A crafted HTTP request allows an attacker to reach functionality that should require valid credentials — without ever authenticating. No stolen session, no brute force, no user interaction. The attacker simply talks to the server.
  2. Unauthenticated code execution: The bypassed functionality exposes a code execution path, allowing the attacker to run arbitrary commands in the context of the HFS process.

The practical consequences depend on how HFS was deployed, and this is where organizations routinely hurt themselves. HFS is frequently launched manually by a user — sometimes an administrator — and left running. If that user is a local admin, the attacker's code execution inherits those privileges. We've seen this exact deployment anti-pattern turn similar file-server RCEs into full domain compromise within a single IR engagement.

Exploitation Status

  • In-the-wild exploitation: CONFIRMED. Attackers are actively exploiting this flaw now — this is not a proof-of-concept stage disclosure.
  • CISA KEV: Monitor the CISA Known Exploited Vulnerabilities catalog — given confirmed active exploitation and a 9.3 CVSS score, KEV inclusion is a strong possibility, which would trigger binding remediation deadlines for federal civilian agencies and should be treated as a de facto deadline by everyone else.

The notable subplot here is the discovery vector: an AI model (Anthropic Mythos) identified the bug. Expect adversaries to apply the same technique. AI-assisted vulnerability discovery is compressing the window between "bug exists" and "working exploit," and defenders should assume that window for internet-facing utilities is now measured in days, not months.

Detection & Response

The most reliable detection signal for post-exploitation of a Windows-hosted HFS instance is hfs.exe spawning child processes — a file-sharing server has virtually no legitimate reason to launch shells, script interpreters, or download utilities. This is a high-fidelity, low-noise detection that every SOC should deploy today, regardless of patch status.

Sigma Rules

YAML
---
title: Rejetto HFS Spawning Shell or Script Interpreter
description: Detects hfs.exe spawning command shells or script interpreters, a strong indicator of post-exploitation activity following CVE-2026-61500 unauthenticated RCE.
references:
  - https://securityaffairs.com/200444/ai/anthropic-mythos-found-a-bug-in-rejetto-hfs-attackers-are-now-exploiting-it.html
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/04/06
id: 8f2a1b3c-4d5e-6f70-8192-a3b4c5d6e7f8
status: experimental
tags:
  - attack.execution
  - attack.t1059
  - attack.t1190
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: '\hfs.exe'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\wmic.exe'
  condition: selection_parent and selection_child
falsepositives:
  - HFS event scripts configured by administrators to run on upload/download events
level: critical
---
title: Rejetto HFS Spawning Download or LOLBin Utility
description: Detects hfs.exe spawning living-off-the-land binaries commonly used by attackers to fetch second-stage payloads after exploiting CVE-2026-61500.
references:
  - https://securityaffairs.com/200444/ai/anthropic-mythos-found-a-bug-in-rejetto-hfs-attackers-are-now-exploiting-it.html
  - https://attack.mitre.org/techniques/T1105/
author: Security Arsenal
date: 2026/04/06
id: 2c7e9d41-5a6b-47c8-9d0e-b1f2a3c4d5e6
status: experimental
tags:
  - attack.command_and_control
  - attack.t1105
  - attack.t1190
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: '\hfs.exe'
  selection_child:
    Image|endswith:
      - '\certutil.exe'
      - '\bitsadmin.exe'
      - '\curl.exe'
      - '\rundll32.exe'
      - '\regsvr32.exe'
      - '\msiexec.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Legitimate HFS event scripting (rare; validate against configured event scripts)
level: high
---
title: Rejetto HFS Execution from Non-Standard or Temporary Path
description: Detects hfs.exe running from user-writable or temporary directories, indicating unauthorized or attacker-deployed instances of the file server.
references:
  - https://securityaffairs.com/200444/ai/anthropic-mythos-found-a-bug-in-rejetto-hfs-attackers-are-now-exploiting-it.html
  - https://attack.mitre.org/techniques/T1105/
author: Security Arsenal
date: 2026/04/06
id: 5d3b8f62-7e1a-49c5-b2d4-e6f7a8b9c0d1
status: experimental
tags:
  - attack.defense_evasion
  - attack.t1036
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith: '\hfs.exe'
  selection_paths:
    Image|contains:
      - '\AppData\Local\Temp\'
      - '\Users\Public\'
      - '\ProgramData\'
      - '\Downloads\'
      - '\Desktop\'
  condition: selection and selection_paths
falsepositives:
  - Users legitimately running portable HFS from Downloads or Desktop (this itself is a policy violation worth surfacing)
level: medium

KQL — Microsoft Sentinel / Defender

The first query hunts post-exploitation behavior in Defender process telemetry. The second finds potentially exposed HFS instances via inbound network connections — useful for discovering shadow-IT deployments you didn't know existed.

KQL — Microsoft Sentinel / Defender
// Hunt 1: HFS spawning child processes (post-exploitation indicator for CVE-2026-61500)
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName =~ "hfs.exe"
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "wscript.exe", "cscript.exe",
                      "mshta.exe", "certutil.exe", "bitsadmin.exe", "curl.exe", "rundll32.exe",
                      "regsvr32.exe", "msiexec.exe", "wmic.exe")
| project TimeGenerated, DeviceName, AccountName, InitiatingProcessCommandLine,
          FileName, ProcessCommandLine, SHA256, ReportId
| order by TimeGenerated desc

// Hunt 2: Discover HFS instances receiving inbound connections (shadow IT / exposure discovery)
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where InitiatingProcessFileName =~ "hfs.exe"
| where ActionType == "InboundConnectionAccepted" or (ActionType == "ConnectionSuccess" and LocalPort in (80, 443, 8080, 8081, 8000))
| summarize FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated),
            RemoteIPs = make_set(RemoteIP), Ports = make_set(LocalPort)
  by DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by LastSeen desc

// Hunt 3: Syslog ingestion path for Linux-hosted HFS (Node.js) spawning shells
Syslog
| where TimeGenerated > ago(14d)
| where ProcessName has_any ("node", "hfs")
| where SyslogMessage has_any ("sh -c", "/bin/bash", "/bin/sh", "curl ", "wget ", "chmod +x")
| project TimeGenerated, Computer, ProcessName, SyslogMessage
| order by TimeGenerated desc

Velociraptor VQL

Use this artifact across your Windows fleet to simultaneously (a) inventory running HFS instances and (b) flag any HFS process that has spawned child processes — covering both asset discovery and active-compromise hunting in one sweep.

VQL — Velociraptor
-- Inventory HFS instances and identify suspicious child processes (CVE-2026-61500 hunt)
SELECT Pid,
       Ppid,
       Name,
       Exe,
       CommandLine,
       Username,
       CreateTime,
       (SELECT Name FROM pslist(pid=Ppid)) AS ParentName,
       (SELECT Exe FROM pslist(pid=Ppid)) AS ParentExe
FROM pslist()
WHERE Name =~ '(?i)hfs\.exe'
   OR ParentExe =~ '(?i)hfs\.exe'

-- Additionally enumerate listening ports owned by hfs.exe to confirm exposure
SELECT Pid,
       Name,
       CommandLine,
       (SELECT Address, Port, Status FROM netstat(pid=Pid)) AS ListeningSockets
FROM pslist()
WHERE Name =~ '(?i)hfs\.exe'

Remediation Script

Run this PowerShell (as Administrator) across Windows endpoints to locate HFS instances, capture evidence before stopping them, and apply interim network-level mitigation until the patched version is deployed.

PowerShell
# CVE-2026-61500 - Rejetto HFS Emergency Response Script
# Run elevated. Captures evidence, stops vulnerable instances, applies interim firewall block.

# --- Step 1: Discover and document running HFS instances ---
$hfsProcesses = Get-Process -Name "hfs" -ErrorAction SilentlyContinue
if ($hfsProcesses) {
    $evidencePath = "$env:ProgramData\HFS_IR_$(Get-Date -Format 'yyyyMMdd_HHmmss')"
    New-Item -ItemType Directory -Path $evidencePath -Force | Out-Null
    $hfsProcesses | ForEach-Object {
        $_ | Select-Object Id, ProcessName, Path, StartTime |
            Export-Csv "$evidencePath\hfs_instances.csv" -NoTypeInformation -Append
        # Capture child processes for IR review BEFORE stopping
        Get-CimInstance Win32_Process -Filter "ParentProcessId=$($_.Id)" |
            Select-Object ProcessId, Name, CommandLine, CreationDate |
            Export-Csv "$evidencePath\hfs_child_processes.csv" -NoTypeInformation -Append
    }
    Write-Host "[+] Evidence captured to $evidencePath" -ForegroundColor Green

    # --- Step 2: Stop vulnerable HFS instances ---
    $hfsProcesses | Stop-Process -Force
    Write-Host "[+] Stopped $($hfsProcesses.Count) HFS instance(s)." -ForegroundColor Yellow
} else {
    Write-Host "[-] No running HFS instances found on this host." -ForegroundColor Cyan
}

# --- Step 3: Interim firewall block on common HFS ports (until patched version deployed) ---
$ruleName = "BLOCK-HFS-CVE-2026-61500"
if (-not (Get-NetFirewallRule -DisplayName $ruleName -ErrorAction SilentlyContinue)) {
    New-NetFirewallRule -DisplayName $ruleName -Direction Inbound -Action Block `
        -Program "*\hfs.exe" -Protocol TCP -Profile Any | Out-Null
    Write-Host "[+] Firewall rule '$ruleName' applied: inbound traffic to hfs.exe blocked." -ForegroundColor Yellow
}

# --- Step 4: Check for persistence mechanisms referencing hfs.exe ---
$autoruns = Get-CimInstance Win32_StartupCommand | Where-Object { $_.Command -match 'hfs\.exe' }
$services = Get-CimInstance Win32_Service | Where-Object { $_.PathName -match 'hfs\.exe' }
$tasks    = Get-ScheduledTask | Where-Object { $_.Actions.Execute -match 'hfs\.exe' }
if ($autoruns -or $services -or $tasks) {
    Write-Host "[!] HFS persistence mechanisms found - investigate before re-enabling:" -ForegroundColor Red
    $autoruns | Format-Table Name, Command, Location
    $services | Format-Table Name, PathName, StartMode
    $tasks    | Format-Table TaskName, TaskPath
}

# --- Step 5: Verify patched version after upgrade ---
# After deploying the patched HFS release from https://github.com/rejetto/hfs/releases,
# confirm the version and remove the interim block:
#   Get-Item "C:\path\to\hfs.exe" | Select-Object -ExpandProperty VersionInfo
#   Remove-NetFirewallRule -DisplayName "BLOCK-HFS-CVE-2026-61500"

Remediation

Treat this with the same urgency as a KEV-listed vulnerability, because it very likely will be one.

Immediate (within 24 hours):

  1. Inventory every HFS instance. Do not rely on your asset management platform — HFS is classic shadow IT. Use the KQL and VQL hunts above, plus network scans for the characteristic HFS web interface on ports 80, 8080, and 8081, including non-standard ports. EDR network telemetry and firewall logs are your friends here.
  2. Take internet-facing instances offline immediately. If an instance is exposed to the internet and running a vulnerable version, assume compromise. Pull it from service, capture forensic evidence (process list, network connections, the HFS virtual file system configuration, and web/access logs), and investigate before redeploying.
  3. Upgrade to the patched release. Download only from the official project at github.com/rejetto/hfs or rejetto.com. Confirm in the release notes that the version you deploy explicitly addresses CVE-2026-61500 — do not assume the latest download is patched without verification.

Short term (this week):

  1. Restrict network exposure. Even patched, HFS should not be internet-facing without a compensating control in front of it. Place it behind a VPN, a reverse proxy with authentication, or a zero-trust access gateway. Restrict by source IP at the firewall where feasible.
  2. Run HFS with least privilege. Never run HFS under an administrator account. Create a dedicated low-privilege service account. If code execution occurs, the blast radius should be a file share — not the box, and certainly not the domain.
  3. Deploy the detections above and alert on any HFS child-process activity as high severity.
  4. Audit HFS configurations. Disable HFS event scripting features you don't use (they turn the server into a sanctioned command-execution channel), require authentication on all accounts, and remove any anonymous access unless strictly required.

Strategic:

  1. Ban or govern the pattern, not just the product. Ad-hoc file-sharing utilities (HFS, and its many cousins) appear on networks precisely because sanctioned alternatives are too painful. If you keep finding HFS in your environment, that's a signal to deploy an approved, managed file-transfer solution — not just to keep playing whack-a-mole.
  2. Compress your patch SLAs for internet-facing services. This bug was found by an AI model and was being exploited almost immediately after disclosure. AI-assisted vulnerability discovery means your time-to-patch assumptions from even two years ago are obsolete. For anything listening on a public interface, "patch within 30 days" is a breach timeline, not a security posture.

The Bigger Picture: AI Found This One. Attackers Have AI Too.

The discovery of CVE-2026-61500 by Anthropic's Mythos model is a milestone, but not a comforting one. The same capability that finds bugs for defenders finds them for adversaries — and adversaries don't file disclosures. The defensive implication is straightforward: your exposure window for internet-facing software is shrinking toward zero. Continuous attack surface monitoring, aggressive patch velocity on edge services, and behavioral detections that fire regardless of which CVE was used (like the hfs.exe child-process rules above) are no longer best practice — they're the baseline.

If you need help validating your exposure, hunting for compromise, or stress-testing your detection coverage against exploitation of edge services like this one, reach out.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.