Breaking
Cyber CrimeDeveloping Story

RCE flaw in Rejetto HFS now exploited

Attackers are exploiting CVE-2026-61500 in Rejetto HFS to bypass authentication and gain remote code execution, according to VulnCheck.

··1 hour ago·4 min read
a close up of a computer with green lights
Photo by Tyler on Unsplash

Threat actors have started exploiting a critical vulnerability in Rejetto HTTP File Server (HFS) that lets them bypass authentication and achieve remote code execution, according to a warning from security firm VulnCheck. The flaw, tracked as CVE-2026-61500, carries a CVSS score of 9.3 and was patched in Rejetto HFS version 3.2.1 on July 13. The exploitation attempts observed so far are small-scale reconnaissance, VulnCheck said on October 2, originating from a China Telecom IP and hitting canaries in Japan and the US.

The generator leak at the root

At the heart of the issue is how Rejetto HFS handles session cookies. The open source file server discloses the output of its non-cryptographic session cookie generator to unauthenticated clients during login, and it also derives the session-cookie signing key from that same generator. The generator was Math.random(), which uses the xorshift128+ algorithm to produce the random value later passed to the server's Node.js web framework Koa for signing those cookies.

Because the algorithm's outputs are reversible, an attacker who collects a small set of login responses can reconstruct the generator's state and recover the signing key. Horizon3.ai explained in a technical report that an attacker able to collect other numbers generated by Math.random() could determine additional generated numbers and forge authentication cookies.

With the recovered key, the attacker can forge valid administrator session cookies, gain elevated access, and execute remote code through the server_code configuration feature. Horizon3.ai researchers uncovered the flaw using Anthropic's Mythos AI model, which applied advanced mathematical reasoning to recognize that Math.random() PRNG outputs could be reversed to reconstruct the secret session-cookie signing key. The security firm discovered the weakness in June.

Exploitation spotted in the wild

On October 2, VulnCheck warned that hackers have begun targeting CVE-2026-61500 as part of small-scale reconnaissance. The attempts originated from a China Telecom IP and hit canaries in Japan and the US. At this stage, the activity appears to be reconnaissance rather than full-scale attacks, but the public availability of technical details and the critical severity of the flaw make it a likely target for broader exploitation.

The vulnerability was patched in Rejetto HFS version 3.2.1, released on July 13. Despite the patch, many installations may remain unpatched, leaving them exposed to authentication bypass and remote code execution. VulnCheck's warning indicates that at least some attackers are actively scanning for vulnerable instances.

Vendor confirmation and patch

Rejetto acknowledged the issue in its advisory. "Multiple security vulnerabilities have been found in all previous versions, potentially allowing an attacker to gain administrative access to HFS," the advisory stated. The fix was included in version 3.2.1.

"Multiple security vulnerabilities have been found in all previous versions, potentially allowing an attacker to gain administrative access to HFS."

— Rejetto, in its advisory

AI's role in discovery

The discovery of CVE-2026-61500 marks another instance where AI-assisted analysis helped identify a critical flaw. Horizon3.ai researchers used Anthropic's Mythos model to reverse-engineer the Math.random() output and reconstruct the session-cookie signing key. The model's mathematical reasoning capabilities allowed it to recognize the reversibility of the xorshift128+ algorithm and the implications for cookie forgery.

While AI tools are increasingly used for vulnerability research, the finding also highlights how a seemingly benign design choice—using a non-cryptographic PRNG for security-sensitive operations—can lead to severe consequences. The flaw existed because the generator's outputs were not cryptographically secure and were leaked to unauthenticated users.

Who is affected and how

Any organization running Rejetto HFS version prior to 3.2.1 is potentially vulnerable. The server is open source and used for file sharing, and successful exploitation grants administrative access and remote code execution. Attackers can then use the server_code configuration feature to run arbitrary code, potentially leading to full system compromise.

The exploitation attempts observed by VulnCheck targeted canaries in Japan and the US, suggesting that attackers are scanning broadly. The origin IP from China Telecom indicates a possible state-linked or criminal actor, though attribution remains unconfirmed.

Mitigation and response

Administrators should upgrade to Rejetto HFS version 3.2.1 or later immediately. Given that exploitation has begun, patching is urgent. Organizations that cannot patch right away should consider blocking or restricting access to HFS instances from untrusted networks.

  • CVE-2026-61500 carries a CVSS score of 9.3.
  • Rejetto HFS version 3.2.1 was released on July 13 with the necessary patches.
  • Exploitation attempts were observed on October 2, originating from a China Telecom IP and hitting canaries in Japan and the US.

Monitoring for anomalous login attempts and unusual server_code configuration changes can help detect exploitation attempts. The vulnerability allows authentication bypass, so any successful login without valid credentials should be treated as suspicious.

Why it matters

The exploitation of CVE-2026-61500 shows how quickly a critical flaw can move from patch to active targeting. For organizations using Rejetto HFS, the window to patch before broader attacks begin may be closing. The involvement of AI in discovering the flaw also suggests that both attackers and defenders will increasingly leverage AI to find and exploit weaknesses. Businesses should review their exposure to HFS and ensure that all instances are updated, as the consequences of a successful attack include full administrative control and remote code execution.

#rejetto#hfs#cve-2026-61500#rce#exploitation

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories