Hackers Actively Probing File Servers for Exploitable Cryptographic Weakness

Security researchers detected active reconnaissance probes targeting CVE-2026-61500, a critical vulnerability in Rejetto HFS file-sharing software that enables attackers to forge administrator sessions and execute remote code. The flaw stems from the use of a weak non-cryptographic random number generator for session cookie signing, which was discovered using AI analysis and disclosed with proof-of-concept code in late September 2026. Early scanning activity appears to originate from China, targeting deployments in Japan and the United States following public release of technical exploitation details.
The vulnerability affects Rejetto HFS versions 3.0.0 through 3.2.0 and was initially disclosed in mid-July 2026. Security researchers from Horizon3 leveraged artificial intelligence technology to identify not just a flawed random number generator used for session authentication, but also a separate code path that inadvertently exposed the generator's outputs to unauthenticated users—creating a complete exploitation chain that attackers could weaponize.
The flaw carries particular risk because HFS includes built-in functionality allowing custom server-side scripting execution. Once an attacker forges administrative credentials, they gain access to this feature, enabling them to run arbitrary code directly on the compromised system. Organizations running outdated versions remain exposed to file theft, malware installation, and lateral movement into internal networks.
This disclosure illustrates mounting pressure on administrators to maintain rapid patch cycles as exploitation timelines accelerate. Organizations deploying older HFS versions in production environments—particularly those managing sensitive files—face elevated compromise risk following public technical details becoming available. The geographic pattern of probing activity suggests targeted reconnaissance rather than indiscriminate attacks, though this distinction may prove temporary if exploit tools become widely accessible. Smaller enterprises and individuals using HFS for legitimate file-sharing purposes may lack resources to prioritize updates quickly.