CRITICALvulnerability·

Rejetto HFS Servers Actively Scanned for Critical RCE Flaw (CVE-2026-61500)

Threat actors are actively scanning for a critical Remote Code Execution (RCE) vulnerability, CVE-2026-61500, affecting Rejetto HFS (HTTP File Server) instances. This flaw, stemming from a weak signing key, allows for session forgery, account takeover, and arbitrary code execution on vulnerable servers. Immediate action is advised for organizations operating Rejetto HFS.

This report was researched and drafted by an AI agent and reviewed by a human analyst prior to publication. View the agent workflow →

Overview

Rejetto HFS servers are currently being targeted by threat actors actively scanning for CVE-2026-61500, a critical vulnerability enabling Remote Code Execution (RCE). This flaw poses a significant risk due to its potential for complete system compromise, session hijacking, and account takeover. Organizations utilizing Rejetto HFS should prioritize assessment and mitigation efforts immediately.

Technical Analysis

The vulnerability, tracked as CVE-2026-61500, is described as a weak signing key issue within Rejetto HFS. This weakness can be exploited to perform session forgery, allowing attackers to hijack legitimate user sessions. More critically, it facilitates account takeover and ultimately leads to Remote Code Execution (RCE) on the underlying server. The specific versions of Rejetto HFS affected are not detailed in the provided source, but the vulnerability is actively being scanned for, indicating widespread potential impact. The attack vector is likely through crafted HTTP requests leveraging the weak signing key mechanism.

Detection

  • Process Creation Anomalies: Monitor for unusual child processes spawned by the hfs.exe process, such as cmd.exe, powershell.exe, sh.exe, or other scripting interpreters, especially with unusual command-line arguments.
  • Web Server Logs: Review HFS access logs for suspicious request patterns, including unusual HTTP methods, large or malformed parameters, or attempts to access administrative endpoints with forged session tokens. Look for unexpected POST requests to sensitive paths.
  • Network Traffic Analysis: Monitor network traffic originating from the HFS server for outbound connections to unknown or suspicious IP addresses, which could indicate post-exploitation activity like C2 communication or data exfiltration.
  • File System Changes: Look for unexpected file creations or modifications in the HFS web root or system directories, potentially indicating webshell deployment or other persistence mechanisms.

Sigma Detection Rules

⚠️ AI-generated detection rules. These are experimental starting points. Review field names, EventIDs, and logic against your environment’s schema before deploying. Tune to reduce false positives.

Rejetto HFS – Suspicious Child Process from hfs.exe

title: Rejetto HFS - Suspicious Child Process from hfs.exe
id: 9a3e4f1b-5c6d-4e7a-8b9c-0d1e2f3a4b5c
status: experimental
description: Detects suspicious process creation by the Rejetto HFS server process, indicative of RCE exploitation (CVE-2026-61500).
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    ParentImage|endswith: '\\hfs.exe'
    Image|endswith:
      - '\\cmd.exe'
      - '\\powershell.exe'
      - '\\pwsh.exe'
      - '\\wscript.exe'
      - '\\cscript.exe'
      - '\\mshta.exe'
      - '\\bitsadmin.exe'
      - '\\certutil.exe'
  condition: selection
level: high

Rejetto HFS – Unusual Outbound Network Connection from hfs.exe

title: Rejetto HFS - Unusual Outbound Network Connection from hfs.exe
id: 6c7d8e9f-0a1b-2c3d-4e5f-6a7b8c9d0e1f
status: experimental
description: Detects outbound network connections initiated by the Rejetto HFS process, which could indicate post-exploitation C2 or data exfiltration after RCE (CVE-2026-61500).
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    Image|endswith: '\\hfs.exe'
    Initiated: 'true'
    DestinationIp|!startswith:
      - '10.'
      - '172.16.'
      - '172.17.'
      - '172.18.'
      - '172.19.'
      - '172.20.'
      - '172.21.'
      - '172.22.'
      - '172.23.'
      - '172.24.'
      - '172.25.'
      - '172.26.'
      - '172.27.'
      - '172.28.'
      - '172.29.'
      - '172.30.'
      - '172.31.'
      - '192.168.'
      - '127.'
  condition: selection
level: medium

Mitigations

  1. Patch or Upgrade: Apply any available patches or upgrade to a non-vulnerable version of Rejetto HFS as soon as they are released by the vendor. (No specific patch information is available at the time of writing).
  2. Restrict Network Access: Limit network access to Rejetto HFS servers from untrusted networks. If possible, place HFS behind a firewall or reverse proxy and restrict access to only necessary IP ranges or internal networks.
  3. Disable Unnecessary Services: If Rejetto HFS is not critical for business operations, consider disabling or uninstalling it until a patch is available.
  4. Implement Web Application Firewall (WAF): Deploy a WAF in front of HFS to detect and block malicious web requests targeting the vulnerability.
  5. Principle of Least Privilege: Ensure the HFS service runs with the minimum necessary privileges to limit the impact of a successful exploit.

References

  • https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/

Indicators of Compromise

No public IOCs available at time of writing.

MITRE ATT&CK

  • T1190 — Exploit Public-Facing Application
  • T1059 — Command and Scripting Interpreter
  • T1078 — Valid Accounts
🤖 AI Attribution
Generated by gemini-2.5-flash ·
1,512 input / 1,623 output tokens ·
Reviewed and approved by a human analyst before publication
#vulnerability#critical#hfs#rce#rejetto#vulnerability#webserver#windows