The Exploit Bulletin

Archives
Log in
Subscribe
October 2, 2026

The Exploit Bulletin — Friday, October 2, 2026: 1 issue requires action

Friday, October 2, 2026 — 1 issue requires action. If you run none of the software below, you are done.

Affects: Rejetto HFS


1. Predictable Math.random() session signing key lets unauthenticated attackers forge admin cookies in Rejetto HFS (CVE-2026-61500)

AUTHENTICATION BYPASS · CRITICAL · CVSS 9.3

A weapon-grade exploit for this unauthenticated no-interaction flaw is published in VulnCheck's XDB (catalogued 2026-10-01) against a file server normally published straight to the internet; no in-the-wild attacks are confirmed, but anything still on 3.2.0 or earlier is one public script away from handing over admin.

HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and leaks outputs of that same generator to unauthenticated clients in login responses. An attacker who collects a handful of login responses can reconstruct the generator state, recover the signing key and forge an administrator session cookie, which yields full admin access and code execution through the server_code configuration feature.

Affected: Rejetto HFS (http_file_server) 3.0.0 through 3.2.0 (fixed in 3.2.1)

How to Test: Check the running version in the HFS admin interface or the application title/about screen; any build from 3.0.0 up to and including 3.2.0 is affected. On affected hosts, review HFS access logs for repeated unauthenticated login requests from a single source followed by authenticated administrator actions, and inspect the HFS configuration for unexpected server_code entries or added accounts, which is the path from forged session to code execution.

How to Patch: Upgrade to Rejetto HFS v3.2.1 (released 2026-07-13, https://github.com/rejetto/hfs/releases/tag/v3.2.1), which the vendor states fixes multiple vulnerabilities allowing administrative access. After upgrading, invalidate existing sessions and change the administrator password so any previously forged or recovered key is useless; where an upgrade must wait, remove the HFS admin interface from internet reachability.

Evidence: VulnCheck KEV · VulnCheck XDB exploit entry for CVE-2026-61500

Full entry with sources →


Read on the web · Every past edition

The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.

Spot an error, or an exploit we missed? Reply here or email [email protected].

Don't miss what's next. Subscribe to The Exploit Bulletin:
← Newer The Exploit Bulletin — Saturday, October 3, 2026: 2 issues require action Older → The Exploit Bulletin — Thursday, October 1, 2026: 3 issues require action
www.exploitbulletin.com
jbac.co
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.