Rejetto HFS Servers Actively Scanned for Critical RCE Flaw (CVE-2026-61500)
Threat actors are actively scanning for a critical Remote Code Execution (RCE) vulnerability, CVE-2026-61500, affecting Rejetto HFS (HTTP File Server) instances. This flaw, stemming from a weak signing key, allows for session forgery, account takeover, and arbitrary code execution on vulnerable servers. Immediate action is advised for organizations operating Rejetto HFS.
Overview
Rejetto HFS servers are currently being targeted by threat actors actively scanning for CVE-2026-61500, a critical vulnerability enabling Remote Code Execution (RCE). This flaw poses a significant risk due to its potential for complete system compromise, session hijacking, and account takeover. Organizations utilizing Rejetto HFS should prioritize assessment and mitigation efforts immediately.
Technical Analysis
The vulnerability, tracked as CVE-2026-61500, is described as a weak signing key issue within Rejetto HFS. This weakness can be exploited to perform session forgery, allowing attackers to hijack legitimate user sessions. More critically, it facilitates account takeover and ultimately leads to Remote Code Execution (RCE) on the underlying server. The specific versions of Rejetto HFS affected are not detailed in the provided source, but the vulnerability is actively being scanned for, indicating widespread potential impact. The attack vector is likely through crafted HTTP requests leveraging the weak signing key mechanism.
Detection
- Process Creation Anomalies: Monitor for unusual child processes spawned by the
hfs.exeprocess, such ascmd.exe,powershell.exe,sh.exe, or other scripting interpreters, especially with unusual command-line arguments. - Web Server Logs: Review HFS access logs for suspicious request patterns, including unusual HTTP methods, large or malformed parameters, or attempts to access administrative endpoints with forged session tokens. Look for unexpected
POSTrequests to sensitive paths. - Network Traffic Analysis: Monitor network traffic originating from the HFS server for outbound connections to unknown or suspicious IP addresses, which could indicate post-exploitation activity like C2 communication or data exfiltration.
- File System Changes: Look for unexpected file creations or modifications in the HFS web root or system directories, potentially indicating webshell deployment or other persistence mechanisms.
Sigma Detection Rules
Rejetto HFS – Suspicious Child Process from hfs.exe
title: Rejetto HFS - Suspicious Child Process from hfs.exe
id: 9a3e4f1b-5c6d-4e7a-8b9c-0d1e2f3a4b5c
status: experimental
description: Detects suspicious process creation by the Rejetto HFS server process, indicative of RCE exploitation (CVE-2026-61500).
logsource:
product: windows
service: sysmon
detection:
selection:
ParentImage|endswith: '\\hfs.exe'
Image|endswith:
- '\\cmd.exe'
- '\\powershell.exe'
- '\\pwsh.exe'
- '\\wscript.exe'
- '\\cscript.exe'
- '\\mshta.exe'
- '\\bitsadmin.exe'
- '\\certutil.exe'
condition: selection
level: high
Rejetto HFS – Unusual Outbound Network Connection from hfs.exe
title: Rejetto HFS - Unusual Outbound Network Connection from hfs.exe
id: 6c7d8e9f-0a1b-2c3d-4e5f-6a7b8c9d0e1f
status: experimental
description: Detects outbound network connections initiated by the Rejetto HFS process, which could indicate post-exploitation C2 or data exfiltration after RCE (CVE-2026-61500).
logsource:
product: windows
service: sysmon
detection:
selection:
Image|endswith: '\\hfs.exe'
Initiated: 'true'
DestinationIp|!startswith:
- '10.'
- '172.16.'
- '172.17.'
- '172.18.'
- '172.19.'
- '172.20.'
- '172.21.'
- '172.22.'
- '172.23.'
- '172.24.'
- '172.25.'
- '172.26.'
- '172.27.'
- '172.28.'
- '172.29.'
- '172.30.'
- '172.31.'
- '192.168.'
- '127.'
condition: selection
level: medium
Mitigations
- Patch or Upgrade: Apply any available patches or upgrade to a non-vulnerable version of Rejetto HFS as soon as they are released by the vendor. (No specific patch information is available at the time of writing).
- Restrict Network Access: Limit network access to Rejetto HFS servers from untrusted networks. If possible, place HFS behind a firewall or reverse proxy and restrict access to only necessary IP ranges or internal networks.
- Disable Unnecessary Services: If Rejetto HFS is not critical for business operations, consider disabling or uninstalling it until a patch is available.
- Implement Web Application Firewall (WAF): Deploy a WAF in front of HFS to detect and block malicious web requests targeting the vulnerability.
- Principle of Least Privilege: Ensure the HFS service runs with the minimum necessary privileges to limit the impact of a successful exploit.
References
- https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/
Indicators of Compromise
No public IOCs available at time of writing.
MITRE ATT&CK
T1190— Exploit Public-Facing ApplicationT1059— Command and Scripting InterpreterT1078— Valid Accounts
Generated by
gemini-2.5-flash ·1,512 input / 1,623 output tokens ·
Reviewed and approved by a human analyst before publication