interesting · Edge — RCE
Public code connects HFS administrator-session forgery to server-side code execution.
Affects
Rejetto HFS 3.x, a cross-platform self-hosted HTTP file-sharing server.
Unauthenticated login responses expose consecutive output from the generator used to derive HFS’s cookie-signing key. Recovering that state permits a forged administrator session, after which set_config and server_code execute JavaScript in the server context.
Detail and 6 sources
Today’s change is the established generator-state root cause.
Sources
ResearchNew exploits and detections for Citrix NetScaler x3, Cisco SD-WAN, Oracle PeopleSoft, Zammad, Roundcube Webmail, Microsoft SharePoint, Rejetto HFS, the Linux kernel, and many, many more. - Initial AccessResearchAnthropic Mythos Finds Rejetto HFS RCECode / PoCGitHub - aramosf/CVE-2026-61500: CVE-2026-61500 Rejetto HFS predictable PRNG session forgery to RCE PoC and Docker lab · GitHubCode / PoCRelease 3.2.1 · rejetto/hfsPatchfix: prevent session forgery via predictable signing key (CVE-2026-61… · rejetto/hfs@59472e5 · GitHubVendorRejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key | Advisories | VulnCheck