Exploitation Hits Rejetto HFS Vulnerability Discovered by AI
Attackers are exploiting Rejetto HFS flaw CVE-2026-61500 to forge admin cookies and gain code execution.
VulnCheck says attackers are exploiting CVE-2026-61500, a CVSS 9.3 flaw in Rejetto HTTP File Server that can bypass authentication and lead to remote code execution. Login responses leak outputs from the non-cryptographic Math.random xorshift128+ generator, allowing an attacker to reconstruct its state, recover the Koa session-cookie signing key, forge administrator cookies, and execute code through the server_code feature. Horizon3.ai discovered the issue in June with Anthropic’s Mythos model, and Rejetto patched it in HFS 3.2.1 on July 13. On October 2, VulnCheck reported small-scale reconnaissance from a China Telecom address against canaries in Japan and the United States.