A Critical Vulnerability in Rejetto HFS Exposes Servers to Remote Code Execution
Threat actors have begun exploiting a critical vulnerability in Rejetto HTTP File Server (HFS) that allows them to bypass authentication and gain remote code execution on vulnerable servers. The flaw, tracked as CVE-2026-61500 with a CVSS score of 9.3, was discovered by AI-powered researchers who used advanced mathematical reasoning to identify the weakness.
The vulnerability exists in Rejetto HFS’s session cookie generator, which uses a non-cryptographic algorithm called xorshift128+ to generate “random” values. These values are then passed to Node.js’s Koa web framework for signing session cookies. However, because the algorithm is reversible, an attacker can collect login responses from the server and use them to recover the secret session-cookie signing key. With this key, attackers can forge valid administrator session cookies, granting them elevated access to the server and enabling remote code execution via the server_code configuration feature.
The issue was uncovered by Horizon3.ai researchers using Anthropic’s Mythos AI model, which identified that Math.random() PRNG outputs could be reversed to reconstruct the secret session cookie signing key. The weakness has been present in all previous versions of Rejetto HFS and was patched in version 3.2.1 released on July 13.
Despite the patches, threat actors have already begun targeting CVE-2026-61500 as part of small-scale reconnaissance efforts originating from a China Telecom IP. Attempts to exploit the vulnerability have been detected in canaries in Japan and the US, highlighting the urgent need for server administrators to update their Rejetto HFS installations.
Rejetto has acknowledged that multiple security vulnerabilities exist in previous versions of its software, potentially allowing attackers to gain administrative access to HFS servers. Server administrators should take immediate action to patch their systems and ensure they are running version 3.2.1 or later. In addition, organizations should review their network logs for signs of reconnaissance activity related to CVE-2026-61500 and consider implementing additional security measures to protect against future exploits.
In the wake of this vulnerability, server administrators would do well to take a closer look at their software configurations and ensure that they are using secure algorithms and protocols to generate session cookies. This includes verifying that any third-party libraries or frameworks used in conjunction with Rejetto HFS are up-to-date and free from vulnerabilities. By taking proactive steps to secure their servers, administrators can help prevent successful exploits of CVE-2026-61500 and maintain the integrity of their network infrastructure.
Source: SecurityWeek — 2026-10-05