Cybersecurity researchers have uncovered a severe vulnerability in the Rejetto HTTP File Server (HFS) that is being actively exploited by threat actors. The flaw, identified as CVE-2026-61500 with a CVSS score of 9.3, allows attackers to bypass authentication mechanisms and execute remote code on susceptible systems, as reported by VulnCheck.
Details of the Rejetto HFS Vulnerability
The vulnerability arises from the server’s non-cryptographic session cookie generator, which leaks crucial outputs to unauthenticated users during the login process. This flaw enables malicious actors to reverse-engineer the session-cookie signing key by analyzing a small number of login responses.
Once the signing key is compromised, attackers can create legitimate-looking administrator session cookies, gaining unauthorized access and executing arbitrary code through the server’s configuration features. This significant security issue is rooted in Rejetto HFS’s use of the xorshift128+ algorithm for generating ‘random’ values, which are then utilized by the Koa web framework in Node.js to sign session cookies.
AI’s Role in Identifying the Flaw
The weakness was detected by researchers at Horizon3.ai through the use of Anthropic’s Mythos AI model. The AI’s advanced mathematical reasoning capabilities identified that the outputs from the Math.random() pseudo-random number generator (PRNG) could be reversed, enabling the reconstruction of the secret session-cookie signing key.
This discovery was made in June, leading to the release of Rejetto HFS version 3.2.1 on July 13, which addressed the vulnerability. Rejetto’s advisory warned of multiple security weaknesses in all previous versions, potentially allowing administrative access to attackers.
Current Exploitation and Security Measures
On October 2, VulnCheck alerted the cybersecurity community that hackers have begun exploiting CVE-2026-61500. These attacks have been traced back to reconnaissance activities originating from a China Telecom IP, specifically targeting canaries in Japan and the United States.
With the vulnerability being actively exploited, organizations using Rejetto HFS are urged to update to the latest patched version immediately to mitigate potential risks. Continuous monitoring and implementing robust security practices are essential to protect against such vulnerabilities.
The exploitation of Rejetto HFS highlights the ongoing challenges in cybersecurity, emphasizing the critical role of AI in identifying and addressing complex security flaws.
