Back to Intelligence

CVE-2026-61500: Rejetto HFS Session Forgery Under Active Exploitation — Detection, Hunting, and Remediation Guide

SA
Security Arsenal Team
October 5, 2026
12 min read

VulnCheck has confirmed that attackers are actively exploiting CVE-2026-61500, a critical vulnerability in Rejetto HTTP File Server (HFS) carrying a CVSS score of 9.3. The flaw is a session forgery condition rooted in a weak pseudo-random number generator (PRNG) that produces a predictable session key. An unauthenticated remote attacker who can predict or brute-force that key can forge an administrative session — and from there, the HFS admin interface provides a direct path to arbitrary code execution on the host.

HFS is popular precisely because it is lightweight and easy to expose: a single binary (or Node-based HFS 3 instance) that turns any Windows or Linux box into a file-sharing server. That same convenience is why it is so frequently internet-facing, often standing up on ad-hoc ports, personal servers, staging boxes, and shadow-IT file drops that never made it into the asset inventory. If you run HFS anywhere reachable from the network — especially the public internet — treat this as an incident-response priority, not a patch-Tuesday line item.


Technical Analysis

Affected Product

  • Product: Rejetto HTTP File Server (HFS) — both the classic Windows build and the actively developed Node.js-based HFS 3.x line are widely deployed; HFS 3 is the current supported branch.
  • Exposure: Any HFS instance with its HTTP(S) listener reachable by an attacker. Internet-exposed instances are the primary target of the observed exploitation.
  • Vulnerability class: CWE-330 (Use of Insufficiently Random Values) / CWE-331 (Insufficient Entropy) leading to CWE-384 (Session Fixation/forgery-equivalent) — session tokens derived from a weak PRNG with insufficient entropy.

CVE and Scoring

AttributeValue
CVECVE-2026-61500
CVSS v3.19.3 (Critical)
Root causeWeak PRNG producing a predictable session key
ImpactAdmin session forgery → full control of the HFS instance → remote code execution on the host
Authentication requiredNone
Exploitation statusConfirmed active exploitation in the wild (per VulnCheck)

How the Attack Works — Defender's View

The kill chain is short and quiet:

  1. Reconnaissance: The attacker identifies an HFS instance. HFS has a distinctive HTTP fingerprint — the Server header, the default HTML template, and characteristic API endpoints such as /~/api/... make trivially easy targets for internet-wide scanning.
  2. Key prediction: Because the session key is generated by a weak PRNG, the keyspace is far smaller than intended. The attacker seeds or narrows the generator state (time-based seeding is the classic failure mode here) and computes candidate session tokens.
  3. Session forgery: The attacker presents a forged admin session token to the HFS API/web interface. From the server's perspective, this is indistinguishable from a legitimate logged-in administrator — there is no password prompt, no MFA challenge, nothing in the authentication logs to trip on.
  4. Post-exploitation / code execution: HFS's administrative functionality allows an operator to influence what the server executes or serves. Attackers leverage admin-level features (custom commands, plugin/script capabilities, or file-write-then-execute patterns) to run arbitrary commands under the HFS service account. On Windows, expect child processes of hfs.exe; on Linux (HFS 3 via Node), expect children of the node process.

Why This Is Dangerous

  • No authentication noise. Session forgery does not produce failed logons. Your "brute force" detections are blind to it.
  • Low exploitation cost. A predictable PRNG means exploitation scales horizontally — this is exactly the kind of bug that gets folded into mass scanners and botnets within days, which matches VulnCheck's observed activity.
  • HFS's historical track record. Rejetto HFS has been a repeat target for mass exploitation in prior years; threat actors already have tooling, fingerprinting logic, and target lists built around this product.
  • Code execution as the end state. This is not a data-leak-only bug. Once admin access is forged, the host itself is compromised.

Detection & Response

The two highest-fidelity detection surfaces are:

  1. Host behavior: the HFS server process (hfs.exe or node running HFS) spawning shells, script interpreters, or tooling it never spawns in normal operation.
  2. Web/API behavior: bursts of requests against HFS API/admin endpoints from single sources (key-guessing), or successful admin API activity from IP addresses with no prior legitimate admin history.

Sigma Rules

YAML
---
title: Rejetto HFS Process Spawning Command Shell or Script Interpreter
id: 3f8a1c94-7b2e-4d51-9a06-c1e2f3a4b5c6
status: experimental
description: Detects the Rejetto HTTP File Server process (hfs.exe or node running HFS) spawning command shells, PowerShell, or other script interpreters — consistent with post-exploitation following CVE-2026-61500 admin session forgery and code execution.
references:
  - https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/10/24
tags:
  - attack.execution
  - attack.t1059
  - attack.initial_access
  - attack.t1190
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\hfs.exe'
      - '\node.exe'
    ParentCommandLine|contains:
      - 'hfs'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\rundll32.exe'
      - '\certutil.exe'
      - '\bitsadmin.exe'
      - '\curl.exe'
      - '\wget.exe'
      - '\whoami.exe'
      - '\net.exe'
      - '\nltest.exe'
  condition: selection_parent and selection_child
falsepositives:
  - HFS admin-configured "run program on event" actions (document and allowlist explicitly)
  - Legitimate Node tooling in development environments — restrict to production HFS hosts
level: high
---
title: Suspicious Reconnaissance or Execution Tooling Launched Under HFS Service Context
id: 8b2d5e17-4c6a-4f89-b3d1-9e0a2c4f6d78
status: experimental
description: Detects discovery and staging commands (whoami, ipconfig, systeminfo, archive creation, base64-encoded commands) executed with a parent process chain rooted in the HFS server, indicating hands-on-keyboard activity after CVE-2026-61500 exploitation.
references:
  - https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html
  - https://attack.mitre.org/techniques/T1033/
  - https://attack.mitre.org/techniques/T1059.001/
author: Security Arsenal
date: 2026/10/24
tags:
  - attack.discovery
  - attack.t1033
  - attack.t1059.001
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\hfs.exe'
      - '\node.exe'
  selection_cli:
    CommandLine|contains:
      - 'whoami'
      - 'systeminfo'
      - 'ipconfig /all'
      - '-enc '
      - '-encodedcommand'
      - 'FromBase64String'
      - 'Invoke-WebRequest'
      - 'Invoke-Expression'
      - 'downloadstring'
      - 'certutil -decode'
      - 'tar.exe -'
      - 'Compress-Archive'
  condition: selection_parent and selection_cli
falsepositives:
  - Rare; HFS does not normally execute discovery or download commands
level: critical
---
title: Potential HFS Session Key Brute-Force or Admin API Probing
id: 1c4e7a26-9d3b-4e58-a7c2-5f1b8d3e9a04
status: experimental
description: Detects high-volume or repeated requests against Rejetto HFS API and admin endpoints from a single source, consistent with session key guessing or forged-session validation attempts against CVE-2026-61500. Apply to web/proxy/firewall logs ingested into a SIEM.
references:
  - https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html
  - https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/10/24
tags:
  - attack.initial_access
  - attack.t1190
  - attack.credential_access
  - attack.t1110
logsource:
  category: webserver
detection:
  selection_uri:
    cs-uri|contains:
      - '/~/api/'
      - '/~/admin'
      - '/~/login'
  condition: selection_uri
falsepositives:
  - Legitimate admin usage — baseline admin source IPs and alert on deviation; tune thresholds to your environment
level: medium

KQL — Microsoft Sentinel / Defender

The following hunt works on two fronts: web-layer requests against HFS API endpoints (via CommonSecurityLog from your reverse proxy/firewall, or Syslog from a Linux-hosted HFS 3 fronted by nginx), and host-layer process lineage on the HFS server itself.

KQL — Microsoft Sentinel / Defender
// Part 1: Web-layer hunt — probing or key-guessing against HFS API/admin endpoints
// Requires HFS fronted by a proxy/firewall shipping CEF/Syslog to Sentinel
let HfsEndpoints = dynamic(["/~/api/", "/~/admin", "/~/login"]);
CommonSecurityLog
| where TimeGenerated > ago(24h)
| where RequestURL has_any (HfsEndpoints)
| summarize
    RequestCount = count(),
    DistinctURIs = dcount(RequestURL),
    FirstSeen = min(TimeGenerated),
    LastSeen = max(TimeGenerated),
    URIs = make_set(RequestURL, 25)
  by SourceIP, DestinationHostName, DestinationPort
| where RequestCount > 20 or DistinctURIs > 5
| order by RequestCount desc;
// Part 2: Host-layer hunt — HFS or node spawning shells/script interpreters (Defender for Endpoint)
DeviceProcessEvents
| where TimeGenerated > ago(24h)
| where InitiatingProcessFileName in~ ("hfs.exe", "node.exe")
   or InitiatingProcessCommandLine has "hfs"
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "wscript.exe",
    "cscript.exe", "mshta.exe", "rundll32.exe", "certutil.exe", "bitsadmin.exe",
    "curl.exe", "wget.exe", "whoami.exe", "net.exe")
| project TimeGenerated, DeviceName, AccountName,
    InitiatingProcessFileName, InitiatingProcessCommandLine,
    FileName, ProcessCommandLine, SHA256
| order by TimeGenerated desc;
// Part 3: Network connections from the HFS process to rare external destinations
DeviceNetworkEvents
| where TimeGenerated > ago(24h)
| where InitiatingProcessFileName in~ ("hfs.exe", "node.exe")
| where RemoteIPType == "Public"
| summarize Connections = count(), Ports = make_set(RemotePort),
    FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
  by DeviceName, RemoteIP, RemoteUrl
| order by Connections asc; // low-volume egress from a file server is the anomaly

Velociraptor VQL

Use this as a fleet-wide hunt artifact to identify potentially compromised HFS hosts: it enumerates running HFS processes, their child processes, and active network connections in one pass.

VQL — Velociraptor
-- Hunt: Rejetto HFS (hfs.exe / node) suspicious child processes and egress
-- Deploy as a hunt across all endpoints hosting file-sharing services
SELECT Pid, Name, CommandLine, Exe, Username, CreateTime,
       Ppid
FROM pslist()
WHERE Name =~ '(?i)hfs|node'
   OR CommandLine =~ '(?i)hfs'

-- Child processes of any HFS/node parent (code execution indicator)
SELECT child.Pid AS ChildPid,
       child.Name AS ChildName,
       child.CommandLine AS ChildCommandLine,
       child.Username AS ChildUser,
       parent.Pid AS ParentPid,
       parent.Name AS ParentName,
       parent.CommandLine AS ParentCommandLine
FROM pslist() AS child
JOIN pslist() AS parent ON child.Ppid = parent.Pid
WHERE parent.Name =~ '(?i)hfs|node'
  AND child.Name =~ '(?i)cmd|powershell|pwsh|wscript|cscript|mshta|rundll32|certutil|whoami|net\.exe|sh|bash|python|perl'

-- Active network connections held by the HFS process (C2 / exfil review)
SELECT Pid, Name, LocalAddress, LocalPort, RemoteAddress, RemotePort, State
FROM netstat()
WHERE Name =~ '(?i)hfs|node'

Triage Script

Run this on suspected HFS hosts to inventory the installation, identify the running version, enumerate child processes of the server, and check for unexpected administrative accounts/config changes.

PowerShell
# Rejetto HFS compromise triage — run elevated on the HFS host
# 1. Locate running HFS processes and their versions
$hfs = Get-Process | Where-Object { $_.Name -match '^(hfs|node)$' } |
  Select-Object Id, Name, Path, StartTime,
    @{N='CommandLine';E={(Get-CimInstance Win32_Process -Filter "ProcessId=$($_.Id)").CommandLine}}
$hfs | Format-List

# 2. Any child processes spawned by HFS (post-exploitation indicator)
foreach ($p in $hfs) {
  Get-CimInstance Win32_Process -Filter "ParentProcessId=$($p.Id)" |
    Select-Object ProcessId, Name, CommandLine, CreationDate | Format-List
}

# 3. HFS config & account review (HFS 3 stores config under the working directory)
#    Look for unexpected admin accounts or plugins added recently
Get-ChildItem -Path "C:\Program Files\hfs","$env:USERPROFILE\hfs",".\" -Recurse -Include config.yaml,*.yaml -ErrorAction SilentlyContinue |
  Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-30) } |
  Select-Object FullName, LastWriteTime

# 4. Recent outbound connections from the HFS process
foreach ($p in $hfs) {
  Get-NetTCPConnection -OwningProcess $p.Id -ErrorAction SilentlyContinue |
    Where-Object { $_.State -eq 'Established' -and $_.RemoteAddress -notmatch '^(127\.|10\.|192\.168\.|172\.(1[6-9]|2[0-9]|3[01])\.)' } |
    Select-Object RemoteAddress, RemotePort, State
}
Bash / Shell
# Linux equivalent for HFS 3 (Node) hosts — run as root
# 1. Find the HFS/node process and its command line
ps -eo pid,ppid,user,lstart,cmd | grep -Ei 'hfs|node' | grep -v grep

# 2. Enumerate children of the HFS process (shells, downloaders = red flag)
for pid in $(pgrep -f 'hfs|node'); do
  echo "=== Children of PID $pid ==="
  ps --ppid "$pid" -o pid,user,lstart,cmd
done

# 3. Recent config changes (new admin accounts / plugins)
find /opt/hfs /srv/hfs ~/hfs -name '*.yaml' -mtime -30 -ls 2>/dev/null

# 4. Outbound connections from the HFS process
for pid in $(pgrep -f 'hfs|node'); do
  ss -tnp | grep "pid=$pid"
done

Remediation

Given confirmed in-the-wild exploitation, sequence your response as follows:

  1. Isolate and inventory now. Identify every HFS instance in your environment — including shadow IT. Scan for listening HTTP services on non-standard ports and fingerprint for HFS response signatures. Any internet-exposed HFS instance should be pulled behind a firewall or taken offline until patched.
  2. Patch immediately. Upgrade to the latest HFS release published by Rejetto. Obtain builds only from the official sources:
  3. Invalidate all existing sessions and rotate credentials. Assume any session key issued by a vulnerable build is predictable. After patching, restart the service, force re-authentication for all users, and rotate every HFS account password. Audit the HFS account list for administrators you did not create.
  4. Hunt before you trust. Because exploitation is confirmed active, do not patch-and-forget. Run the KQL/VQL hunts above over the past 30 days of telemetry. Review HFS config for added admin accounts, plugins, custom scripts, or "run on event" actions. Check the host for unexpected child processes of hfs.exe/node, new local accounts, persistence mechanisms, and egress connections.
  5. Reduce the attack surface. If HFS does not require public exposure, bind it to internal interfaces only and front it with a VPN or zero-trust access proxy. Restrict the HFS service account to least privilege — it should never run as SYSTEM, Administrator, or root. Block outbound internet access from the HFS host except to explicitly required destinations.
  6. Monitor for re-exploitation. Deploy the Sigma rules above to your SIEM/EDR. Alert on any HTTP 200 response to HFS admin API endpoints from source IPs outside your known administrator set — a forged session succeeds silently, so post-auth behavioral monitoring is your tripwire.
  7. If compromise is confirmed: treat the host as fully compromised. Acquire memory and disk before remediation, rotate any credentials that ever transited or resided on the host, and scope lateral movement from the HFS machine — it is frequently a workstation or a server with broad internal reach.

The defensive lesson here extends beyond Rejetto: any application that derives session tokens from a weak PRNG is one seed-recovery away from full auth bypass. During your next application-security review, ask every vendor how session entropy is generated — and demand CSPRNG-backed token generation in writing.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.