The Rejetto HTTP File Server (HFS) is currently facing active exploitation attempts due to a significant security vulnerability, as reported by VulnCheck. This flaw, identified as CVE-2026-61500 with a CVSS score of 9.3, arises from an inadequate pseudo-random number generator (PRNG), which results in a predictable session key. This vulnerability permits attackers to gain unauthorized access and potentially control affected systems.
Understanding the Vulnerability
Spanning versions 3.0.0 through 3.2.0 of Rejetto HFS, the vulnerability involves the derivation of a session-cookie signing key from the non-cryptographic Math.random() function. The system inadvertently reveals outputs from this generator to unauthenticated users during the login process. This flaw allows a remote threat actor to intercept login responses, recreate the generator’s state, retrieve the signing key, and forge a valid administrator session cookie. Consequently, this leads to complete administrative access and the ability to execute arbitrary remote code via the server’s code configuration feature.
Exploitation and Detection
On September 30, 2026, researcher Zach Hanley from Horizon3.ai elucidated on the vulnerability, discovered using Anthropic’s Mythos model. Hanley outlined the flaw as enabling an authentication bypass, which facilitates remote code execution on Rejetto HFS. The administrative API of HFS supports custom endpoints capable of executing arbitrary JavaScript, presenting a clear path from unauthorized access to administrative control and remote code execution.
Although a patch was introduced in July 2026 with version 3.2.1, public disclosure of a Python-based proof-of-concept (PoC) exploit by Alejandro Ramos followed in late September. Ramos highlighted that HFS’s use of the Math.random() function in generating Koa session-cookie signing keys, combined with the exposure during SRP login, allows attackers to reconstruct the PRNG state, forge session cookies, and execute server-side JavaScript.
Current Exploitation Efforts
VulnCheck’s Patrick Garrity reported exploitation attempts detected on October 1, 2026, shortly after Horizon3.ai released further details. The cybersecurity firm identified a threat actor based in China targeting vulnerable servers in the United States. This vulnerability marks the second active exploitation event involving Rejetto HFS, following CVE-2024-23692, which was exploited to deliver malicious payloads such as cryptocurrency miners and malware in mid-2024.
As security threats continue to evolve, addressing such vulnerabilities is critical for safeguarding systems against unauthorized access and potential cyberattacks. Staying informed and applying necessary patches promptly can mitigate risks associated with these exploits.
