The Exploit Bulletin — Friday, October 2, 2026: 1 issue requires action
Friday, October 2, 2026 — 1 issue requires action. If you run none of the software below, you are done.
Affects: Rejetto HFS
1. Predictable Math.random() session signing key lets unauthenticated attackers forge admin cookies in Rejetto HFS (CVE-2026-61500)
AUTHENTICATION BYPASS · CRITICAL · CVSS 9.3
A weapon-grade exploit for this unauthenticated no-interaction flaw is published in VulnCheck's XDB (catalogued 2026-10-01) against a file server normally published straight to the internet; no in-the-wild attacks are confirmed, but anything still on 3.2.0 or earlier is one public script away from handing over admin.
HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and leaks outputs of that same generator to unauthenticated clients in login responses. An attacker who collects a handful of login responses can reconstruct the generator state, recover the signing key and forge an administrator session cookie, which yields full admin access and code execution through the server_code configuration feature.
Affected: Rejetto HFS (http_file_server) 3.0.0 through 3.2.0 (fixed in 3.2.1)
How to Test: Check the running version in the HFS admin interface or the application title/about screen; any build from 3.0.0 up to and including 3.2.0 is affected. On affected hosts, review HFS access logs for repeated unauthenticated login requests from a single source followed by authenticated administrator actions, and inspect the HFS configuration for unexpected server_code entries or added accounts, which is the path from forged session to code execution.
How to Patch: Upgrade to Rejetto HFS v3.2.1 (released 2026-07-13, https://github.com/rejetto/hfs/releases/tag/v3.2.1), which the vendor states fixes multiple vulnerabilities allowing administrative access. After upgrading, invalidate existing sessions and change the administrator password so any previously forged or recovered key is useless; where an upgrade must wait, remove the HFS admin interface from internet reachability.
Evidence: VulnCheck KEV · VulnCheck XDB exploit entry for CVE-2026-61500
Read on the web · Every past edition
The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.
Spot an error, or an exploit we missed? Reply here or email [email protected].