CVE-2024-23692Active Exploitation(rejetto / http_file_server)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for rejetto http_file_server systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-07-30. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-1336CWE-94

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_file_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-04); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
http_file_server

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-05-04: 2Mentions · 2026-10-05: 2Active Exploitation · 2026-05-04: 1Technical Details · 2026-05-04: 105-0410-05
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets3 URLs
Full discourse4 posts
  • Juan F Gallego@jfernandogg

    Ya hay intentos de explotación contra CVE-2026-61500 (CVSS 9.3) en Rejetto HFS: con unas pocas respuestas de login se reconstruye el generador Math.random(), se recupera la llave que firma las cookies y se fabrica una sesión de admin. De ahí a RCE vía server_code. Afecta HFS 3.0.0 a 3.2.0; el fix (3.2.1) salió el 13 de julio. El PoC público llegó a finales de septiembre y VulnCheck vio los primeros intentos el 1 de octubre, un día después del write-up de http://Horizon3.ai: reconocimiento desde una IP de China Telecom contra canaries en Japón y EE. UU. Dato aparte: Horizon3 encontró la falla con el modelo Mythos de Anthropic. Es la segunda falla de HFS explotada, después de CVE-2024-23692. Acción: 3.2.1 o superior, sacarlo de internet si no hace falta y revisar sesiones admin y cambios de configuración.

    0001039
    347 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2024-23692: Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.

    Post summary

    CVE-2024-23692 describes a template engine flaw in Rejetto HTTP File Server that allows remote command execution via crafted HTTP requests, but no PoC, exploit code, active exploitation, or patch information is provided.

    1000039
    152 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows attackers exploiting CVE-2024-23692 in Rejetto HFS servers by reconstructing weak session signing keys to forge administrator cookies. Following initial compromise, threat actors escalate privileges and move laterally to internal systems. Runtime segmentation helps contain post-compromise activity. 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw

    0000050
    2.0K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2024-23692-http-file-server #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The reference indicates that CVE-2024-23692, an HTTP File Server vulnerability, is being exploited in the wild, but no proof‑of‑concept, exploit code, or detailed technical information is provided in the text.

    0000034
    152 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprejettohttp_file_server---

Explore more