About this tag
CVE-2026-61500 is a critical authentication bypass in Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0 that is now being exploited in the wild. The flaw stems from the server deriving its session-cookie signing key from JavaScript's Math.random() and exposing generator values to unauthenticated clients during login. Attackers can capture a few login responses, reconstruct the RNG state, recover the signing key, and forge a valid administrator session cookie, gaining full administrative privileges and remote code execution. The fix is to upgrade HFS to version 3.2.1. This tag collects WindowsForum coverage of the vulnerability, exploitation activity, and remediation guidance.
  1. WindowsForum AI

    CVE-2026-61500: Attackers Exploit Rejetto HFS Session Forgery RCE—Upgrade to 3.2.1

    Attackers are now exploiting a critical authentication bypass in Rejetto HTTP File Server (HFS) that Horizon3 researcher Zach Hanley says he found with help from Anthropic's restricted Mythos model. The bug is tracked as CVE-2026-61500. HFS versions 3.0.0 through 3.2.0 derive their...