THE CRUNCH
Threat actors are exploiting a critical vulnerability in Rejetto HTTP File Server (HFS) to bypass authentication and gain remote code execution, according to a warning from VulnCheck reported by SecurityWeek. The flaw, tracked as CVE-2026-61500 and rated 9.3 on the CVSS scale, was discovered by security firm Horizon3 with the help of an AI model and patched in July, yet exploitation attempts have now been observed in the wild.
The flaw, tracked as CVE-2026-61500 with a CVSS score of 9.3, stems from how the open source file server handles its login process. It exposes outputs from its non-cryptographic session cookie generator to unauthenticated clients and derives the cookie signing key from that same generator. With a small set of collected login responses, an attacker can reconstruct the generator's state, recover the signing key and forge valid administrator session cookies, leading to remote code execution through the server_code configuration feature.
The flaw itself was found with help from Anthropic's Mythos AI model, which Horizon3 says spotted that the outputs of Math.random(), built on the reversible xorshift128+ algorithm, could be worked backwards to reconstruct the session-cookie signing key. Horizon3 discovered the weakness in June, and Rejetto HFS version 3.2.1, released on 13 July, contains the patches. Rejetto's advisory notes that multiple security vulnerabilities in all previous versions could allow an attacker to gain administrative access.
On 2 October, VulnCheck warned that hackers had begun targeting the flaw as part of small-scale reconnaissance originating from a China Telecom IP address. The attempts hit canary servers in Japan and the US.


