Rejetto HTTP File Server (HFS) — the lightweight, Node.js-based file-sharing server beloved by home labs, small businesses, and (unfortunately) a surprising number of production environments — is under active attack. CVE-2026-61500 allows a remote, unauthenticated attacker to recover the server's session-cookie signing key, forge an administrative session cookie, and pivot directly to remote code execution on the host. The vulnerability was discovered using AI-assisted vulnerability research, and according to SecurityWeek's reporting, exploitation has already begun in the wild.
This is the nightmare scenario for an internet-exposed file server: no credentials required, a deterministic path to admin, and a built-in mechanism (HFS's admin panel and command execution features) to turn that admin session into code running as the HFS service account. If you run HFS 3.x anywhere reachable from the internet — or honestly, anywhere reachable from anything — treat this as a drop-everything patch event.
HFS has been here before. CVE-2024-23692 gave attackers unauthenticated RCE in HFS 2.x and was hammered by botnets for months. Defenders who still have legacy HFS instances in their environment should take CVE-2026-61500 as the final push to inventory, patch, or retire them.
Technical Analysis
Affected Products
- Product: Rejetto HTTP File Server (HFS) version 3.x (the Node.js rewrite, distributed as a single binary
hfs.exe/hfsor via npm ashfs) - Platforms: Windows, Linux, and macOS — HFS 3 is cross-platform, so the blast radius spans all three
- Component: Session-cookie signing / authentication subsystem
The Vulnerability
CVE-2026-61500 is a cryptographic weakness in how HFS derives or protects the secret key used to sign session cookies. An attacker who can interact with the server's HTTP interface can recover that signing key. Once the key is recovered, the attack chain is brutally simple:
- Key recovery: The attacker sends crafted requests to the HFS web interface and, through the weakness in the signing-key handling, reconstructs the secret used to sign session cookies.
- Session forgery: With the signing key in hand, the attacker mints a valid session cookie for the built-in admin account — no password, no MFA prompt, no brute force. The server accepts it because the signature is cryptographically valid.
- Administrative access: The forged admin session grants full access to the HFS admin panel, including configuration, file system control over shared roots, and user management.
- Code execution: HFS's administrative functionality can be abused to execute operating-system commands on the host (for example, via admin-level plugin/configuration features), yielding RCE in the context of the HFS process — which in many real-world deployments runs as an elevated or highly privileged service account.
This is a pre-authentication bug. There is no exploitation prerequisite other than network reachability to the HFS HTTP port (default 8080).
Exploitation Status
- Active exploitation confirmed. SecurityWeek reports that exploitation of CVE-2026-61500 has begun in the wild shortly after disclosure.
- Discovered via AI-assisted research. The flaw was identified using AI-driven vulnerability discovery — a signal that the window between disclosure and weaponization of cryptographic auth flaws in edge-facing software will continue to shrink. Defenders should assume automated scanning and mass exploitation are underway.
- Verify CISA KEV status at cisa.gov/known-exploited-vulnerabilities-catalog; if listed, federal civilian agencies face a Binding Operational Directive deadline, and private-sector teams should treat that date as their own SLA.
Why This Is Worse Than It Looks
HFS is frequently deployed by non-security staff to solve an immediate "I need to share files" problem. That means: shadow IT, no inventory entry, default ports, no WAF, no logging pipeline, and often running as root/SYSTEM "because it didn't work otherwise." A pre-auth key-recovery-to-RCE chain against that deployment profile is catastrophic. The first step of your response is finding the servers you don't know about.
Detection & Response
Detection strategy for CVE-2026-61500 centers on three observable behaviors: (1) the HFS process spawning child processes or shells, which it should essentially never do in normal operation; (2) anomalous HTTP traffic to HFS admin endpoints consistent with session forgery and post-exploitation; and (3) network reconnaissance of port 8080 indicating you're on someone's target list.
Sigma Rules
---
title: Rejetto HFS Process Spawning Shell or Script Interpreter
id: 8c1e4a92-3b7f-4d51-9a6c-2e8f0b1d7a34
status: experimental
description: Detects the HFS server process spawning command shells or script interpreters, consistent with post-exploitation of CVE-2026-61500 after forged admin session access. HFS has no legitimate reason to spawn cmd.exe, powershell.exe, sh, or bash.
references:
- https://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/06/15
tags:
- attack.execution
- attack.t1059
- attack.initial_access
- attack.t1190
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\hfs.exe'
- '\node.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
condition: selection_parent and selection_child
falsepositives:
- Extremely rare; custom HFS admin plugins invoking scripts. Investigate every hit.
level: critical
---
title: Rejetto HFS Spawning Shell on Linux or macOS
id: 3f7b2d18-6a4c-4e90-b851-9d2c5f7e1a60
status: experimental
description: Detects the HFS server process spawning shells on Linux/macOS hosts, indicative of CVE-2026-61500 post-exploitation command execution.
references:
- https://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/
- https://attack.mitre.org/techniques/T1059.004/
author: Security Arsenal
date: 2026/06/15
tags:
- attack.execution
- attack.t1059.004
- attack.initial_access
- attack.t1190
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- '/hfs'
- '/node'
selection_child:
Image|endswith:
- '/sh'
- '/bash'
- '/zsh'
- '/dash'
- '/python'
- '/python3'
- '/perl'
- '/curl'
- '/wget'
condition: selection_parent and selection_child
falsepositives:
- Custom admin plugins invoking system commands. Treat every alert as an incident until ruled out.
level: critical
---
title: Suspicious HTTP Requests to HFS Administrative Interface
id: 6d9a3f04-1c8e-4b27-a392-5f0e7c4d9b12
status: experimental
description: Detects inbound requests to HFS admin and API endpoints from external or untrusted sources, consistent with session-cookie forging and admin panel abuse following CVE-2026-61500 key recovery. Tune the uri paths to your HFS version's admin routes.
references:
- https://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/
- https://attack.mitre.org/techniques/T1190/
- https://attack.mitre.org/techniques/T1078/
author: Security Arsenal
date: 2026/06/15
tags:
- attack.initial_access
- attack.t1190
- attack.valid_accounts
- attack.t1078
logsource:
category: webserver
detection:
selection:
cs-uri|contains:
- '/~/admin/'
- '/~/api/'
filter_listen_port:
dst-port: 8080
condition: selection and filter_listen_port
falsepositives:
- Legitimate admin access from known administrator source IPs. Allowlist your admin subnets explicitly and alert on everything else.
level: high
The first two rules are close to zero-noise: a file server process spawning a shell is an incident, full stop. The webserver rule requires tuning to your environment — restrict alerting to requests from outside known admin source ranges, and it becomes a high-fidelity tripwire for forged-session admin access.
Microsoft Sentinel / Defender KQL
This hunt covers HFS on Windows endpoints via Defender process telemetry, and Linux HFS hosts via Syslog ingestion. Run it across at least the last 30 days to catch exploitation that predated disclosure.
// Hunt: HFS server spawning child processes (post-exploitation of CVE-2026-61500)
// Windows hosts via Defender for Endpoint
let HfsProcs = dynamic(["hfs.exe", "node.exe"]);
let SuspiciousChildren = dynamic(["cmd.exe", "powershell.exe", "pwsh.exe", "mshta.exe",
"wscript.exe", "cscript.exe", "rundll32.exe", "certutil.exe", "bitsadmin.exe",
"net.exe", "net1.exe", "whoami.exe", "nltest.exe"]);
DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName in~ (HfsProcs)
| where FileName in~ (SuspiciousChildren)
| project TimeGenerated, DeviceName, AccountName, InitiatingProcessFileName,
InitiatingProcessCommandLine, FileName, ProcessCommandLine, SHA256, ReportId
| order by TimeGenerated desc;
// Linux HFS hosts via Syslog (sudo/exec capture) — look for shells under node/hfs
Syslog
| where TimeGenerated > ago(30d)
| where ProcessName =~ "node" or SyslogMessage has_cs "hfs"
| where SyslogMessage has_any ("/bin/sh", "/bin/bash", "curl", "wget", "chmod +x")
| project TimeGenerated, Computer, ProcessName, SyslogMessage
| order by TimeGenerated desc;
// Network reconnaissance: inbound connection attempts to HFS default port
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where LocalPort == 8080
| where ActionType == "InboundConnectionAccepted"
| summarize ConnectionCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
by RemoteIP, DeviceName
| where ConnectionCount > 50
| order by ConnectionCount desc;
Velociraptor VQL
Use this artifact to sweep your fleet for HFS processes and any suspicious children — critical for finding shadow-IT HFS deployments you didn't know existed.
-- Hunt for Rejetto HFS processes and suspicious child processes (CVE-2026-61500)
-- Deploy as a fleet-wide hunt to inventory HFS and flag post-exploitation behavior
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)hfs'
OR (Name =~ '(?i)node' AND CommandLine =~ '(?i)hfs')
OR CommandLine =~ '(?i)hfs.*--port'
-- Follow-up: identify any child processes spawned by the HFS process
LET hfs_pids = SELECT Pid FROM pslist() WHERE Name =~ '(?i)hfs'
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Ppid in (SELECT Pid FROM hfs_pids)
AND Name =~ '(?i)(cmd|powershell|pwsh|sh|bash|python|curl|wget|mshta|certutil)'
-- Check for HFS listening on its default port (exposure validation)
SELECT Pid, Name, LocalAddress, LocalPort, RemoteAddress, RemotePort, State
FROM netstat()
WHERE LocalPort == 8080 AND State =~ 'LISTEN'
Remediation / Hardening Script
Run this on Windows hosts to inventory HFS, check versions, and apply compensating controls while you patch. A Bash equivalent is included for Linux hosts.
# CVE-2026-61500 - Rejetto HFS inventory, containment, and verification
# Run elevated. Test in a staging environment before broad deployment.
# --- Step 1: Discover HFS processes and binaries on the host
$hfsProcs = Get-Process | Where-Object { $_.Name -match 'hfs' -or ($_.Name -eq 'node' -and $_.CommandLine -match 'hfs') }
if ($hfsProcs) {
Write-Host "[!] HFS process detected:" -ForegroundColor Red
$hfsProcs | Select-Object Id, Name, Path, CommandLine | Format-List
} else {
Write-Host "[+] No running HFS process found." -ForegroundColor Green
}
# --- Step 2: Check listening ports for HFS (default 8080)
Get-NetTCPConnection -State Listen -ErrorAction SilentlyContinue |
Where-Object { $_.LocalPort -in 80, 443, 8080 } |
ForEach-Object {
$owner = (Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue)
if ($owner.Name -match 'hfs|node') {
Write-Host "[!] HFS listening on port $($_.LocalPort) as PID $($_.OwningProcess) ($($owner.Path))" -ForegroundColor Red
}
}
# --- Step 3: Retrieve installed HFS version (npm installs)
$npmHfs = npm list -g hfs 2>$null
if ($npmHfs -match 'hfs@') { Write-Host "[*] Installed HFS version: $npmHfs" }
# --- Step 4: CONTAINMENT - block inbound 8080 at the host firewall until patched
# This is a compensating control, NOT a fix. Patch first.
New-NetFirewallRule -DisplayName "CONTAIN-CVE-2026-61500-HFS-8080-Block" `
-Direction Inbound -Protocol TCP -LocalPort 8080 -Action Block `
-ErrorAction SilentlyContinue | Out-Null
Write-Host "[*] Inbound TCP 8080 blocked at host firewall (containment). Remove after patching."
# --- Step 5: Audit for child processes spawned by HFS in recent event logs (Sysmon)
Get-WinEvent -FilterHashtable @{ LogName='Microsoft-Windows-Sysmon/Operational'; Id=1; StartTime=(Get-Date).AddDays(-30) } `
-ErrorAction SilentlyContinue |
Where-Object { $_.Message -match 'ParentImage:.*(hfs\.exe|node\.exe)' } |
Select-Object TimeCreated, Message | Format-List
Write-Host "[*] Sysmon audit complete. Any hits above = investigate as active compromise."
#!/usr/bin/env bash
# CVE-2026-61500 - Rejetto HFS inventory and containment for Linux hosts
set -euo pipefail
# --- Step 1: Find running HFS processes
if pgrep -fa 'hfs' > /dev/null; then
echo "[!] HFS process detected:"
pgrep -fa 'hfs'
else
echo "[+] No HFS process running."
fi
# --- Step 2: Identify listeners on common HFS ports
ss -tlnp | grep -E ':(80|443|8080)\s' | grep -Ei 'hfs|node' || echo "[+] No HFS listener found."
# --- Step 3: Check globally installed npm HFS version
npm list -g hfs 2>/dev/null | grep 'hfs@' || echo "[*] HFS not installed via global npm."
# --- Step 4: Containment - block inbound 8080 via nftables until patched
nft add rule inet filter input tcp dport 8080 drop 2>/dev/null \
&& echo "[*] Inbound TCP 8080 dropped (containment). Remove after patching." \
|| echo "[!] nftables rule failed - apply network-level ACL instead."
# --- Step 5: Check for suspicious children of HFS in audit logs
if command -v ausearch &>/dev/null; then
ausearch -ts recent -k exec 2>/dev/null | grep -Ei 'hfs|node' | grep -E '/bin/(sh|bash)|curl|wget' \
&& echo "[!] Suspicious child process activity - investigate immediately."
fi
echo "[*] Complete. Patch HFS to the fixed release and rotate all secrets."
Remediation
- Patch immediately. Upgrade HFS 3 to the latest fixed release from the official repository at github.com/rejetto/hfs or via
npm update -g hfs. Check the project's security advisories at github.com/rejetto/hfs/security/advisories for the exact fixed version addressing CVE-2026-61500. Do not rely on firewall rules as a substitute for the patch — the bug is in the crypto, not the perimeter. - Rotate the signing key and all credentials. Patching stops new key recovery, but if your key was already recovered, every forged session remains valid until the key changes. Regenerate the session signing secret (delete/rotate HFS's stored config/secret material), invalidate all active sessions, and reset every HFS account password — especially admin.
- Remove internet exposure. HFS should never be directly internet-facing. Place it behind a VPN, an authenticated reverse proxy (with its own auth layer), or an allowlist ACL. If business requirements demand external file sharing, use a managed platform — HFS is a convenience tool, not a hardened edge service.
- Restrict admin access. Bind the admin interface to localhost or a dedicated management network. Where the version supports it, enforce admin-API access by source IP allowlist.
- Drop privileges. If the HFS service runs as root, SYSTEM, or Administrator, fix that today. A dedicated, minimally-privileged service account with filesystem access scoped only to the shared roots dramatically reduces post-exploitation impact.
- Hunt before you patch. Because exploitation predates public disclosure for many victims, assume compromise for any HFS instance that was internet-reachable. Run the KQL/VQL hunts above across 30+ days of telemetry. Look specifically for HFS child processes, new local accounts, unexpected outbound connections from the HFS host, and webshells or unfamiliar files dropped into HFS's shared directories.
- Fix the inventory problem. The reason bugs like this sting is shadow deployments. Add HFS fingerprinting (port 8080, HFS server banner,
/~/URI structure) to your attack-surface management scans so the next CVE doesn't require an emergency scavenger hunt.
Executive Takeaways
CVE-2026-61500 compresses the entire kill chain into one bug: no credentials, key recovery, forged admin session, code execution. It was found by AI — which means the next one will be found faster, and exploited faster still. The durable defensive lessons: know what you run, keep convenience software off the internet, and treat any pre-auth flaw in an internet-reachable service as an incident, not a ticket.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.