Skip to content
Bellator Cyber Guard
News7 min readStandard

AI-Found Rejetto HFS Flaw Now Under Active Attack

CVE-2026-61500 lets attackers steal Rejetto HFS's session-cookie signing key for admin access and remote code execution. Active exploitation reported.

By Bellator Cyber Guard Security Team
AI-Found Rejetto HFS Flaw Now Under Active Attack - rejetto hfs cve 2026 61500 active exploitation update 2026

CVE-2026-61500 Lets Attackers Forge Admin Sessions on Rejetto HFS

A newly disclosed vulnerability in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, is now being actively exploited, according to an October 5, 2026 report from SecurityWeek. Rejetto HFS is free, lightweight file-sharing server software for Windows that lets a user turn any folder into a browser-accessible download point, a tool commonly used by small offices, IT administrators, and solo operators for quick, no-frills file distribution. The flaw lets an attacker recover the secret key HFS uses to cryptographically sign session cookies. With that key in hand, an attacker can forge a valid administrator session without ever logging in, then use that access to achieve remote code execution (RCE), meaning they can run arbitrary commands on the server as if they were sitting at the keyboard.

What makes this disclosure notable beyond the technical severity is how the flaw was found: according to the source report, CVE-2026-61500 was discovered by an AI system rather than a human researcher working through code by hand. That detail matters for defenders, not just for researchers, and we unpack why below.

How a Stolen Signing Key Becomes Full Server Takeover

Most web applications, including file servers like HFS, use a secret signing key to generate session cookies: small tokens stored in a user's browser that prove they are logged in and tell the server what privilege level they hold. The server trusts a cookie's claims only because it can verify the cookie was signed with a key only the server should know. If that key is exposed or can be recovered, as CVE-2026-61500 reportedly allows, an attacker can manufacture their own cookie claiming administrator rights. Authentication becomes meaningless at that point, because the attacker never needs a valid password; they simply mint the credential they want.

From an administrator session, HFS exposes file upload and server management functions that, per the reported vulnerability chain, can be abused to reach remote code execution. That is the difference between a nuisance bug and a server compromise: once an attacker can execute code, they control the host, not just the file share running on it. Rejetto HFS has drawn attacker interest before; the software has a documented history of being scanned for and targeted opportunistically once vulnerabilities surface, largely because many deployments are exposed directly to the internet for convenience rather than placed behind authentication gateways or VPNs.

Why AI-Discovered Flaws Change the Patching Timeline

AI-assisted vulnerability research tools are increasingly finding exploitable bugs in widely deployed software faster than traditional manual code review historically allowed. For defenders, the practical effect is a shorter runway between a flaw becoming known and it being weaponized. The gap organizations used to count on, where unpatched software had weeks or months before attackers noticed, is shrinking as both defenders and attackers adopt AI-driven discovery and exploit-development tooling. Whether this specific flaw was reported to Rejetto through coordinated disclosure or surfaced some other way was not detailed in the available reporting, but the active exploitation reported by SecurityWeek on October 5, 2026 suggests whatever window existed for quiet patching has already closed for at least some internet-facing deployments.

Key Takeaway

If your organization runs Rejetto HFS anywhere, including an ad hoc file share someone set up years ago and forgot about, treat CVE-2026-61500 as urgent. A forged admin session on this software can lead directly to remote code execution and full host compromise, and exploitation is already reported in the wild as of October 2026.

What Small Businesses, Healthcare Practices, and Tax Firms Should Do Now

First, find out if Rejetto HFS is actually running anywhere on your network. It is common for small practices to stand up a quick file server for a one-time transfer and then leave it running indefinitely, forgotten but still reachable from the internet. Check your firewall rules and any internet-facing port scans for HFS's default listening behavior, and ask IT staff or contractors directly whether anyone has deployed it.

Second, if HFS is in use, check for a vendor-issued update addressing CVE-2026-61500 and apply it immediately. Until a server is patched, take it offline or restrict access to a VPN or an allowlist of trusted IP addresses rather than leaving it open to the public internet, since opportunistic scanning for known HFS flaws has historically picked up quickly after disclosure.

Third, assume compromise is possible on any unpatched, internet-exposed instance: review logs for unexpected administrator logins, unfamiliar user accounts, unexplained file uploads, or outbound connections from the HFS host, and force a reset of any credentials or secrets tied to that server.

Finally, use this as a prompt to reconsider whether a general-purpose file server like HFS is the right tool for sensitive data. Healthcare practices handling protected health information should evaluate file-transfer tools against HIPAA Security Rule access control and transmission security requirements, and tax professionals should weigh client data transfer methods against the data safeguards described in IRS Publication 4557. A single forgotten file server with weak session security is a disproportionate amount of risk for the convenience it provides.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

People also look for

Keep exploring Security basics

Start with the fundamentals, understand the most likely risks, and choose the next improvement without getting lost in jargon.

Learn first. Decide when you are ready.

Keep learning, or apply this to your situation

Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.