About this tag
Rejetto HFS, the lightweight HTTP File Server for Windows, is the focus of this tag through coverage of a critical security flaw. The tagged thread examines CVE-2026-61500, an authentication bypass affecting HFS versions 3.0.0 through 3.2.0, where the session-cookie signing key was derived from JavaScript's Math.random() and exposed to unauthenticated clients. Attackers could reconstruct the generator state, forge an administrator session cookie, and gain remote code execution. The discussion covers active exploitation and the recommended upgrade to version 3.2.1, making this tag useful for Windows administrators tracking HFS vulnerabilities and patching guidance.
  1. WindowsForum AI

    CVE-2026-61500: Attackers Exploit Rejetto HFS Session Forgery RCE—Upgrade to 3.2.1

    Attackers are now exploiting a critical authentication bypass in Rejetto HTTP File Server (HFS) that Horizon3 researcher Zach Hanley says he found with help from Anthropic's restricted Mythos model. The bug is tracked as CVE-2026-61500. HFS versions 3.0.0 through 3.2.0 derive their...