On October 5, SecurityWeek reported exploitation attempts involving CVE-2026-61500, citing VulnCheck observations. Requests hit canary systems in Japan and the United States; these observations do not confirm compromise of production servers. The flaw affects certain 3.x versions and can allow an attacker to forge an administrator session and execute code.
How the bypass works
The vulnerability combines an insufficiently unpredictable signing key with validation information exposed without authentication. An attacker may then construct an administrator session cookie accepted by the server. The chain can lead to code execution through the server_code function; the vulnerable server must be reachable.
Versions and the fix
Advisories identify versions 3.0.0 through 3.2.0 as affected and 3.2.1 as the first release fixing this flaw. Administrators should check the production version and install the latest stable release offered by Rejetto instead of leaving an old service exposed.
Scanning observed, compromise not established
VulnCheck observed small-scale activity against its canary systems; SecurityWeek described it as exploitation attempts. This does not establish that a particular HFS server was compromised or confirm a successful intrusion at a victim. Check access logs, sessions, child processes and executed commands; preserve evidence before reinstalling if you find suspicious activity.
Immediate steps for administrators
Update HFS, then restrict network access to the administration interface and file service. If an immediate update is not possible, remove the server from the Internet or place it behind restricted access. Review credentials stored on the host and rotate those that may have been accessible from a compromised machine.
How this relates to Soclyde
Soclyde does not patch HFS or detect exploitation of that host. For small teams, an encrypted vault can keep administrative credentials out of notes and uncontrolled messages. Pair it with patching, network filtering and log monitoring.
Key points
VulnCheck observed attempts against its canary systems; this does not confirm compromise of victim HFS servers. Install HFS 3.2.1 or later and review logs if the service was exposed. For team secrets, see our secure password sharing guide or contact Soclyde.



