A critical vulnerability tracked as CVE-2026-61500 affects Rejetto HFS versions 3.0.0 through 3.2.0, allowing unauthenticated attackers to forge administrator session cookies. The flaw stems from HFS deriving its session-cookie signing key from JavaScript's non-cryptographic Math.random() generator while also exposing outputs from that same generator during login, giving remote attackers enough information to reconstruct the generator state and recover the signing key.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A vulnerability affecting Rejetto HFS versions 3.0.0 through 3.2.0 was disclosed, describing how use of Math.random() for the session-cookie signing key and leaked RNG outputs during login could let an unauthenticated attacker forge an administrator session. The issue can lead to full administrative access and remote code execution, and the advisory references HFS 3.2.1 as the fix.
Rejetto released HFS version 3.2.1 on 2026-07-13 after multiple security vulnerabilities were found in all previous versions that could allow an attacker to gain administrative access. The release credits Zach Hanley of Horizon3.ai in collaboration with Claude and Anthropic Research.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.