Attackers have begun probing internet-facing Rejetto HFS servers for a flaw that permits session forgery, account takeover and remote code execution. The activity targets CVE-2026-61500, a weak signing key vulnerability in the free and open-source file-sharing tool. VulnCheck, a security research firm, detected the scanning through its Canary Intelligence honeypot network.
Caitlin Condon, VulnCheck's vice president of security research, said in a LinkedIn post over the weekend that the probes appear to be limited reconnaissance. She attributed the activity to a single China Telecom IP address and said it was aimed at deployments in Japan and the United States. The company has not disclosed any successful exploitation or post-exploitation activity.
Rejetto HFS is used for self-hosted file sharing on Windows, Linux and macOS. The flaw was found by researchers at Horizon3, who used Anthropic's Mythos model to uncover it. The model identified both the weak signing-key generation and a separate leak that allowed the key to be recovered.
Horizon3 published details on the flaw and a proof-of-concept exploit on September 30, 2026. The researchers said Mythos did not merely flag the insecure PRNG on its own; it recognized that the application leaked raw Math.random() outputs through a separate code path, connected the two findings into a chain, and concluded the leak produced exactly the observations required to make state recovery feasible. Their exploit shows the chain being used to abuse HFS's built-in ability to run custom server-side JavaScript and achieve remote code execution.
The publication of those technical details may have driven the current probing of CVE-2026-61500. Potential attack scenarios include reading, stealing or deleting files on an HFS server, installing malware on the host, or using a compromised machine to reach internal systems. Users of Rejetto HFS are advised to upgrade to version 3.2.1 or, preferably, the latest stable release, 3.3.4, as soon as possible.
More cybersecurity news from TechManNews.







