Cyber Threat Brief — October 4 2026
1. Rejetto HFS admin session forgery — CVE-2026-61500
TL;DR: VulnCheck canaries started seeing CVE-2026-61500 on the evening of 2026-10-01, the day after Horizon3 published the chain. Find self-hosted Rejetto HFS and get vulnerable hosts off the internet before you review the login API and server_code.
What’s New:
- This is not in CISA KEV. Catalog 2026.10.02 (count 1733) still omits it. VulnCheck put it on its own KEV after canary hits on 2026-10-01.
- Horizon3’s 2026-09-30 write-up says the session signing key comes from
Math.random()whenCOOKIE_SIGN_KEYSis unset, and login leaks later outputs from that same generator. A forged admin session can run JavaScript through theserver_codesetting. - The Register, quoting VulnCheck’s Patrick Garrity, says Thursday night traffic used one China-hosted IP against hosts in the US and Japan. That address was not published. On Friday he reported four hits from 173.239.211.248 and 173.239.211.249, which he called proxy-like.
- VulnCheck counts roughly 100 internet-facing HFS hosts. PoC repo
aramosf/CVE-2026-61500was created on 2026-09-26. No Nuclei template was on nuclei-templates main.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| Rejetto HFS 3.0.0 through 3.2.0 (VulnCheck and the NVD-style advisory text). First fixed release is 3.2.1. SXZ notes 3.3.4 (2026-09-30) lists further security fixes from a different reporter. | Vulnerable app | T1190 | Package inventory / HFS startup banner Version / image tag | List every self-hosted HFS version. If it is 3.0.0 through 3.2.0, upgrade to 3.2.1 or later, or remove it from the network. Prefer a current release such as 3.3.4 when you can, because that tag carries extra fixes beyond this CVE. |
HTTP API path /~/api/loginSrp1 | Login leak / exploit trace | T1190 | HFS access log logs/access.log under the process working directory (non-Windows default cwd is ~/.hfs unless --cwd is set), or the reverse proxy in front of HFS | Alert on repeated requests to /~/api/loginSrp1 from one client. Horizon3’s chain samples that API 12 times. The public PoC sends six unauthenticated loginSrp1 calls for the username admin. A single interactive login is not this pattern. |
config.yaml key server_code | Post-exploitation config | T1059.007 | HFS working directory config.yaml (same cwd as the access log) | Read server_code in config.yaml. If that value is not empty and you did not put it there, treat the host as code-executed and rebuild it. |
Environment variable COOKIE_SIGN_KEYS unset, so the key falls back to randomId(30) | Weak signing key | T1550.004 | Process environment / container env / service unit | On any host still below 3.2.1, set a long random COOKIE_SIGN_KEYS value only as a bridge. The PoC README says that stops signing-key prediction. Upgrade remains the fix. Restarting with a new key invalidates old session cookies. |
| Source IPs 173.239.211.248 and 173.239.211.249 | Network indicator | T1190 | Firewall / reverse proxy / HFS logs/access.log | Search access logs and the edge firewall for 173.239.211.248 and 173.239.211.249. Garrity described those Friday hits as proxy-like. A hit is a lead, not proof the rest of the campaign used only these two addresses. |
Session field allow_session_ip_change set true inside a forged admin cookie whose username is admin | Forged session | T1563 | HTTP cookie on /~/api/ requests, or HFS session store | Decode koa-session cookies on /~/api/ traffic and flag username admin together with allow_session_ip_change true when that login did not come from your admin network. Horizon3 says the attacker signs that field themselves so the IP check does not stop the forgery. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | Web Servers Executing Suspicious Processes needs dest_category=web_server plus whoami, ping, iptables, wget, service, or curl. It does not look at /~/api/loginSrp1. |
| Elastic | None — verified | Suspicious Command Execution via Web Server parents are nginx, Apache, PHP, Java app servers, and similar. node and HFS are not in that parent list, and the child must be a shell with -c. |
| Sigma | None — verified | Rejetto HTTP File Server RCE matches ?search=%00{. for CVE-2014-6287. It does not match /~/api/loginSrp1 or server_code. |
Hunt hint: Record the HFS version from the startup banner before you patch. Copy logs/access.log and config.yaml from the working directory. Count /~/api/loginSrp1 by client. Six or twelve calls in a burst, especially for username admin, matches the published chain better than one normal login. Then read server_code. If it is populated and not yours, rebuild the host and rotate any credentials stored in the shared folders. Move 3.0.0 through 3.2.0 to 3.2.1 or later.
Sources: Horizon3 · VulnCheck advisory · VulnCheck Initial Access 2026-10-02 · The Register · PoC repo · HFS 3.2.0 API mount · SXZ timeline
2. OmniRoute custom-agent command execution — CVE-2026-88062
TL;DR: VulnCheck says CVE-2026-88062 was already hitting canaries in the week ending 2026-10-02. If an OmniRoute management port is reachable with login disabled, block POST /api/acp/agents until you can prove the build contains the fix commit.
What’s New:
- Vendor GHSA-hf57-cqmx-p4gr, published 2026-09-03, says affected versions are below 3.8.49 and that 3.8.49 is patched. Do not stop there.
- Fix commit
60829241carries package version 3.8.50. GitLab’s advisory still says versions through 3.8.50 are affected and that no solution is available. The Nuclei template title says below 3.8.49, its description says 3.8.49 and earlier, and its remediation says to wait for a fix. - Anonymous code execution needs
requireLogin=false, or a fresh instance with no management password, where POST /api/settings/require-login can turn login off. A normal install with a management password needs a session or an API key. - VulnCheck’s 26 Sep–2 Oct note says exploitation includes its canaries. It published no IP, hash, or dropped-file name. PoC-in-GitHub had no entry. A Nuclei template is on main.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
npm package omniroute below the disputed fix line. GHSA says patched at 3.8.49. Commit 60829241 is package 3.8.50. GitLab still lists through 3.8.50 with no solution. | Vulnerable app | T1190 | Image tag / npm ls omniroute / package.json version | Do not treat 3.8.49 as closed. Move to a build you can tie to commit 60829241 (that commit’s package.json says 3.8.50) or a newer release you have diffed against it. Until then, keep the management API off the internet. |
POST /api/acp/agents JSON fields binary and versionCommand | Exploit request | T1190 / T1059.007 | Reverse proxy / HTTP access log / app request log | Alert on POST /api/acp/agents where binary is node and versionCommand starts with node -e. The vendor advisory says that pair passes the self-check and execFileSync runs it. Investigate even if the response is HTTP 401, because that shows probing. |
POST /api/settings/require-login with body requireLogin false | Auth downgrade | T1078 | Same HTTP access log as /api/acp/agents | Alert on POST /api/settings/require-login that sets requireLogin to false from an IP that is not your admin network. The GHSA says an unauthenticated caller can do this only while no management password is set. |
Setting requireLogin=false on a running OmniRoute instance | Exposure | T1190 | OmniRoute settings store / admin UI | Find every instance with requireLogin=false. Turn it on and set a management password, or remove the service from untrusted networks. Anonymous POST /api/acp/agents is the GHSA’s unauthenticated case. |
| Published reproduction listener TCP/20128 | Exposure | T1190 | Firewall / cloud security group / image port map | Block inbound TCP/20128 from the internet. The vendor reproduction publishes container port TCP/20128. Your install may use another port. Close whichever port actually serves /api/acp/agents. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | Web Servers Executing Suspicious Processes still requires whoami, ping, iptables, wget, service, or curl on a host tagged web_server. A node -e child of OmniRoute is none of those. |
| Elastic | None — verified | Suspicious Command Execution via Web Server requires a shell child (bash, sh, and the rest of that list) with -c, and a parent such as nginx or Apache. The GHSA sink is execFileSync of node, whose parent is node, not those servers. |
| Sigma | None — verified | Linux Suspicious Child Process from Node.js - React2Shell only selects parents whose command line contains Next.js or react-scripts markers. Potential RCE Exploitation Attempt In NodeJS looks for the string node:child_process in Node error logs, which a successful execFileSync does not have to emit. |
Hunt hint: Inventory omniroute versions and whether requireLogin is false. On the proxy, search for POST /api/acp/agents and for POST /api/settings/require-login. Then on the host, look for a node process with argument -e whose parent is also node inside the OmniRoute container. A hit means treat that container as untrusted: replace it from a known image, rotate the management password and API keys, and review data under the container data directory. Do not assume 3.8.49 is the fixed build while GitLab and the fix commit disagree.
Sources: GHSA-hf57-cqmx-p4gr · GitLab advisory · SecureLayer7 · VulnCheck Initial Access 2026-10-02 · Fix commit 60829241 · Nuclei template
Status Updates
- CVE-2026-104286 (FortiMail): KEV due TODAY 2026-10-04; forensic triage Yes. FG-IR-26-175 still lists fixed builds as upcoming (8.0.2, 7.6.7, 7.4.9; 7.2 moves to the 7.4 branch). Keep the
/data/etc/ld.so.preloadandliblog.sohunts, and the IBE workaround. Oct 2 brief. - CVE-2026-102489 (Zammad): KEV due TOMORROW 2026-10-05; forensic triage Yes. Session hijack to code as
zammadon 6.3.0–6.5.4. Interim build 7.2.0. Oct 3 brief. - CVE-2026-102490 (Zammad): KEV due TOMORROW 2026-10-05; forensic triage Yes. Local
zammadto root. No confirmed fixed build. Oct 3 brief. - CVE-2026-88779 (NetScaler): CTX697174 (2026-10-03 PST) is a SAML SP or IdP memory-overflow denial of service. Fixed builds 14.1-73.41, 13.1-64.28, FIPS 14.1-73.41, and NDcPP 13.1-37.282. Not in KEV, and the bulletin does not call it code execution. Oct 1 brief.
- CVE-2026-76504 (Cisco Catalyst SD-WAN Manager): KEV due was 2026-10-03; forensic triage Yes. Confirm fixed builds and keep hunting URI-encoded
j_security_check. Oct 1 brief. - CVE-2026-86950 (Apple CoreGraphics): KEV due was 2026-10-02; forensic triage Yes. Confirm iOS/iPadOS 26.7.1, Tahoe 26.7.1 (25G241), Sequoia 15.8.1 (24H32). Sep 29 brief.
- CVE-2026-88771 (Citrix NetScaler): KEV due was 2026-09-30. No new implant in the pages read today. Keep LevelBlue
sec_monitor/.local_journaland Mandiant WHIPSHOT/SLAPSHOT hunts. Oct 1 brief. - CVE-2026-88772 (Citrix NetScaler DTLS): KEV due was 2026-09-30. Confirm fixed builds. DTLS-off is temporary only for this CVE. Sep 28 brief.
- GHSA-qx49-fqc8-xw99 (MCP Python SDK OAuth): No material change. Keep
mcp≥1.30.0 / ≥2.2.0 andissuer=on unattended providers. Sep 29 brief. - CVE-2026-65660 (SharePoint): KEV due was 2026-09-28. Confirm fixed builds and
sphealth.aspxhunts. Sep 26 brief. - CVE-2026-67279 (MikroTik): KEV due was 2026-09-28. Confirm RouterOS ≥6.49.21 / ≥7.23.4 / ≥7.24.2. Sep 06 brief.
- CVE-2026-87902 (WordPress): KEV due was 2026-09-28. Confirm WP ≥7.1.2. Sep 24 brief.
- Carbonato / CVE-2026-62062 (Elementor): No material change. Keep TCP/2375,
GH0ST/SOUL.md, andelementor/v1/events/hunts. Elementor ≥4.3.2. Sep 28 brief.