AI Discovers Critical Rejetto HFS Vulnerability Exploited
Threat actors are leveraging a critical flaw in Rejetto HTTP File Server (HFS) to bypass authentication mechanisms and achieve remote code execution (RCE), according to security researchers.
Vulnerability Overview
The vulnerability, designated CVE-2026-61500 with a CVSS score of 9.3, arises from the open-source file server’s exposure of non-cryptographic session cookie generation outputs to unauthenticated users during login. This flaw also enables the derivation of the session-cookie signing key from the same generator, creating a pathway for attackers to compromise system integrity.
Technical Details
The vulnerability stems from the use of the Math.random() function in Rejetto HFS, which employs the xorshift128+ algorithm to generate random values for session cookies. These values are then processed by the server’s Node.js web framework, Koa, to sign session cookies. Due to the reversible nature of the xorshift128+ algorithm, an attacker with access to multiple outputs from Math.random() can reconstruct the generator’s internal state and recover the session-cookie signing key. This allows adversaries to forge administrator-level session cookies, granting elevated access and enabling RCE through the server_code configuration feature.
Research and Patch
The flaw was identified by Horizon3.ai researchers using Anthropic’s Mythos AI model, which applied advanced mathematical reasoning to detect the reversibility of Math.random() outputs. The researchers discovered the issue in June 2026, prompting Rejetto to release version 3.2.1 of HFS on July 13, 2026, which includes mitigations. Rejetto’s advisory highlighted that all prior versions contain multiple vulnerabilities that could allow attackers to attain administrative control of HFS.
Exploitation and Impact
On October 2, 2026, VulnCheck reported that threat actors have initiated targeted reconnaissance campaigns exploiting CVE-2026-61500. These efforts originated from IP addresses associated with China Telecom and targeted honeypots in Japan and the United States. The exploitation attempts underscore the urgency for organizations using unpatched HFS instances to apply the latest updates.
Security Recommendations
The vulnerability’s exploitation chain relies on the predictable nature of non-cryptographic random number generators, a known risk in systems that prioritize convenience over security. Security professionals emphasize that the flaw highlights the importance of adopting cryptographically secure methods for session management and regularly auditing third-party components for exposure risks. Organizations are advised to review their HFS deployments, apply the patched version, and monitor for signs of unauthorized access.
Conclusion
The incident also serves as a cautionary example of how AI-driven analysis can uncover complex security flaws, reinforcing the need for continuous innovation in threat detection and mitigation strategies.
“The flaw was identified by Horizon3.ai researchers using Anthropic’s Mythos AI model, which applied advanced mathematical reasoning to detect the reversibility of Math.random() outputs.”
