| | |

Rejetto HFS CVE-2026-61500: AI-Found RCE Now Under Attack

A flaw that Horizon3.ai found with Anthropic’s Mythos model lets anyone who can reach a Rejetto HFS 3.x server forge an administrator login and run code on it. The full research went public on September 30. Within days, honeypots recorded the first probes. The patch has been sitting on GitHub since July.

DataWater Threat Intelligence Desk | Published October 6, 2026 | 7-minute read

Threat level: High

New McAfee Banner
Keeper Confetti Image

What: CVE-2026-61500, a session-forgery flaw in Rejetto HTTP File Server (HFS) 3.0.0 through 3.2.0 caused by a weak random number generator (CWE-338). Rated CVSS 4.0 9.3 and CVSS 3.1 9.8 by VulnCheck, the assigning CNA.

Status: Exploitation attempts observed in the wild by VulnCheck, described as small-scale reconnaissance so far. No confirmed successful compromises have been reported.

Deadline: None set. As of October 6, 2026, CVE-2026-61500 is not listed in CISA’s Known Exploited Vulnerabilities catalog, so there is no federal due date. Do not wait for one.

Fix: Upgrade to HFS 3.2.1 (released July 13, 2026) or later; BleepingComputer reports 3.3.4 as the current stable release. If you cannot upgrade today, take HFS off the internet.

Key takeaways

  • CVE-2026-61500 gives an unauthenticated attacker admin access to Rejetto HFS, and admin access in HFS leads straight to code execution on the host.
  • Affected: Rejetto HFS 3.0.0 through 3.2.0. Fixed: HFS 3.2.1 and later.
  • Root cause: HFS signed session cookies with a key built from JavaScript’s Math.random(), and leaked outputs of that same generator to anyone attempting to log in.
  • It was found by AI. Horizon3.ai credits Anthropic’s Mythos model, running in its research harness, with spotting the chain and producing a working proof of concept.
  • Probing began within days of the public write-up, from a single China Telecom IP address hitting VulnCheck honeypots in Japan and the US.

Executive Summary

The window between “research published” and “attackers knocking” is now measured in days, even for a bug that was patched three months ago.

Rejetto HFS is a free, lightweight web file server, popular for quick file sharing and often stood up outside normal IT change control. CVE-2026-61500 affects the 3.x line. The server derived the secret it uses to sign session cookies from Math.random(), a generator built for speed rather than secrecy. Worse, the login process handed unauthenticated visitors raw outputs from that same generator. Collect enough of those outputs and you can rebuild the generator’s internal state, work backward to the signing key, and mint yourself an administrator cookie.

The maintainer shipped a fix in HFS 3.2.1 on July 13, 2026, and VulnCheck published the CVE the same day. Horizon3.ai released its full technical write-up on September 30. VulnCheck’s canary network then logged exploitation attempts: The Hacker News dates the first activity to October 1, while SecurityWeek and Security Affairs cite October 2.

The bottom line: any HFS 3.x server below 3.2.1 that faces the internet should be upgraded or pulled offline today, and checked for unexpected admin activity.

Why This Matters to CISOs and Security Leaders

HFS is shadow IT by design. It is a single-binary tool people run to share a folder fast. That means it often lives on a workstation or a forgotten VM, outside your asset inventory and vulnerability scanner. You may have it and not know it.

Admin means code execution. HFS lets administrators define custom server-side JavaScript. Once an attacker holds a forged admin session, that feature becomes a remote shell running with the privileges of the HFS process.

AI just compressed the research cycle. This is a concrete, public example of a frontier model finding a real, exploitable chain in production software, followed by real-world probing. DataWater has tracked how quickly AI offensive capability is scaling and how attacker speed is outpacing enterprise defenses. CVE-2026-61500 is what that looks like at the level of a single CVE.

Executive insight

The risk here is not the sophistication of the bug. It is that the fix shipped in July and the exploit recipe went public in September. Organizations that only patch what CISA lists will miss this one: it carries a 9.8 CVSS 3.1 score, it is being probed, and it has no KEV entry.

The Timeline

Date (2026) What happened
June Horizon3.ai identifies the flaw using Anthropic’s Mythos model (per SecurityWeek)
Monday, Jul 13 Rejetto releases HFS 3.2.1 with security fixes; VulnCheck publishes CVE-2026-61500
Wednesday, Sep 30 Horizon3.ai publishes its technical write-up; The Hacker News reports a separate public Python proof of concept the same day
Oct 1–2 VulnCheck canaries record exploitation attempts from a China Telecom IP (sources differ on the exact day)
Oct 5 BleepingComputer, SecurityWeek and The Hacker News report active probing
Oct 6 No CISA KEV listing as of this briefing

The patch is three months old. The exploit recipe is one week old. That gap is where attackers live.

Vulnerability & Exploit Analysis

What CVE-2026-61500 is

Three weaknesses combine. First, HFS 3.x builds its cookie-signing key from consecutive Math.random() calls at startup. Second, V8’s implementation of Math.random() uses the xorshift128+ algorithm, which is mathematically reversible once you have enough outputs. Third, an unauthenticated login endpoint exposes raw values from that same generator. Horizon3.ai reports that Mythos recognized the chain, suggested the Z3 constraint solver to recover the generator state, and produced working proof-of-concept code. According to Horizon3.ai’s write-up (single-source detail), roughly a dozen login requests are enough, and the published chain also uses a separate information leak to identify a valid admin username first.

With the signing key recovered, the attacker forges an admin cookie, then uses HFS’s custom server-code feature to execute commands. The CVE record describes the same end state: session forgery leading to remote code execution.

Affected and fixed versions

Product Vulnerable Fix
Rejetto HFS 3.x 3.0.0 – 3.2.0 3.2.1 or later (released July 13, 2026)
Rejetto HFS current stable Not affected 3.3.4 per BleepingComputer
Rejetto HFS 2.x (legacy) Not covered by this CVE Separate history: CVE-2024-23692 (CVSS 9.8) was previously exploited, per The Hacker News
What nobody is talking about
Upgrading closes the hole, but it does not undo a forged session or remove anything an attacker planted with admin rights. If your HFS server was exposed after September 30 on a vulnerable build, check its configuration for custom server code you did not write before you declare victory. The fix and the cleanup are separate jobs.

Exposure

None of the sources reviewed for this briefing published an internet-wide count of exposed HFS 3.x servers. The scale of exposure is unknown. What matters is whether you run HFS anywhere reachable from the internet.

Threat Intelligence Breakdown

Attribution: Unknown. VulnCheck observed reconnaissance from one IP address on China Telecom’s network, targeting canaries in Japan and the United States. One source IP on a large ISP is not attribution, and no threat actor has been named.

Scope: Reporting describes the activity as small-scale and reconnaissance-only. No successful compromises or post-exploitation activity have been publicly confirmed.

Indicators of compromise: No source reviewed for this briefing published IP addresses, hashes or other IoCs for CVE-2026-61500 activity. Focus on behavioral signs instead: bursts of unauthenticated login requests, admin sessions from unfamiliar addresses, and unexpected changes to HFS server-code settings.

Enterprise Impact: What’s Actually at Risk

The files themselves: HFS exists to serve files. An attacker with admin rights can read, replace or delete everything it shares, and swap legitimate downloads for malicious ones.

The host: Code execution runs with the HFS process’s privileges. On a workstation where a user launched it, that may be the user’s full account.

The network behind it: A compromised file server inside the perimeter is a launch point for lateral movement, with no EDR alert tied to the initial entry.

Governance: If the server was unmanaged shadow IT, you may also have a policy problem: an internet-facing service nobody approved, holding data nobody classified.

What Security Leaders Should Do Next

Today

  1. Find every HFS instance. Search asset inventories, EDR software lists and external attack-surface scans for Rejetto HFS, including test and personal machines.
  2. Upgrade to HFS 3.2.1 or later, preferably the current stable release, and confirm the running version.
  3. If you cannot upgrade immediately, remove internet access to the HFS port or shut the service down.

Within 48 hours

  1. Review HFS logs for repeated unauthenticated login attempts and admin sessions since September 30.
  2. Inspect HFS configuration for custom server-side code or new accounts you did not create.
  3. If anything is unexplained, treat the host as compromised: isolate it, rebuild it, and rotate any credentials stored on or used from it.

Long-term

  1. Do not let KEV be your only trigger. Track vendor fixes plus public exploit releases for internet-facing tools.
  2. Bring ad-hoc file sharing under policy. Offer a sanctioned alternative so staff stop standing up their own servers.
  3. Plan for AI-speed research. Assume a public write-up means exploitation within days, and shorten patch windows for exposed services accordingly.

Get zero-day alerts before they hit the headlines

DataWater’s executive threat briefing: the exploited CVEs, the deadlines and the first three actions to take.

Read more briefings

Winners and Losers

Better positioned More exposed
Teams that upgraded HFS in July when 3.2.1 shipped Instances still on 3.0.0–3.2.0 facing the internet
Organizations with external attack-surface monitoring Organizations where HFS runs as unmanaged shadow IT
Defenders using AI-assisted research to find bugs first Small open-source projects without security review resources
Teams that patch on public exploit release, not just KEV Teams waiting for a CISA due date that may never come

Final Executive Takeaway

CVE-2026-61500 is a small product with a big lesson.

An AI model found a real exploit chain, the fix shipped quietly, and attackers started probing within days of the details going public. The defense is not complicated: know where HFS runs, upgrade it, and check what changed while it was exposed.

Find it. Patch it. Check it. Then fix the process that let it go unnoticed.

Frequently Asked Questions

What is CVE-2026-61500?

CVE-2026-61500 is a critical session-forgery vulnerability in Rejetto HTTP File Server (HFS) 3.0.0 through 3.2.0. HFS derived its cookie-signing key from the non-cryptographic Math.random() generator and leaked that generator’s outputs during login, letting an unauthenticated attacker forge an administrator session and then execute code. VulnCheck rates it CVSS 4.0 9.3 and CVSS 3.1 9.8.

Is CVE-2026-61500 being exploited?

Yes, at a limited level. VulnCheck reported exploitation attempts against its honeypots in early October 2026 from a single China Telecom IP address, targeting deployments in Japan and the United States. Reporting describes the Rejetto HFS activity as reconnaissance, with no confirmed successful compromises as of October 6, 2026.

Which Rejetto HFS versions are affected, and how do I fix CVE-2026-61500?

Rejetto HFS 3.0.0 through 3.2.0 are affected by CVE-2026-61500. Upgrade to HFS 3.2.1, released July 13, 2026, or any later version; BleepingComputer cites 3.3.4 as the current stable release.

Is CVE-2026-61500 in the CISA KEV catalog?

Not as of October 6, 2026. The Rejetto HFS flaw CVE-2026-61500 has no CISA Known Exploited Vulnerabilities entry and therefore no federal due date, but it is already being probed, so organizations should patch without waiting for a listing.

How was CVE-2026-61500 discovered?

Horizon3.ai researcher Zach Hanley found the Rejetto HFS flaw using Anthropic’s Mythos model in Horizon3’s research harness. The vendor’s release notes and VulnCheck’s advisory credit Hanley in collaboration with Claude and Anthropic Research.

How do I check whether my Rejetto HFS server was compromised through CVE-2026-61500?

No IoCs have been published for CVE-2026-61500. Review Rejetto HFS logs for bursts of unauthenticated login attempts and unfamiliar admin sessions since September 30, 2026, and inspect the configuration for custom server-side code or accounts you did not create. If anything is unexplained, isolate and rebuild the host and rotate its credentials.

What can I do if I cannot upgrade Rejetto HFS right away?

Remove internet access to the Rejetto HFS service or stop it until you can install 3.2.1 or later. The sources reviewed describe no configuration workaround for CVE-2026-61500, so restricting exposure is the only interim control.

Sources

Primary sources: Horizon3.ai technical disclosure; Rejetto HFS release history; CVE Program record for CVE-2026-61500; and the CISA Known Exploited Vulnerabilities catalog, checked October 6, 2026. Additional reporting reviewed: VulnCheck, The Hacker News, BleepingComputer, SecurityWeek and Security Affairs.

Similar Posts