Security researchers are warning that hackers have started actively scanning for a critical vulnerability in Rejetto HTTP File Server (HFS), a free, open-source file-sharing tool used across Windows, Linux, and macOS deployments. The flaw, tracked as CVE-2026-61500 with a CVSS score of 9.3, allows attackers to forge administrator session cookies and achieve remote code execution.
According to VulnCheck, which first disclosed the targeting activity, its Canary Intelligence honeypots detected probes against the vulnerability over the weekend. VP of Security Research Caitlin Condon said the activity appears to be small-scale reconnaissance originating from a single China Telecom IP address, hitting honeypot deployments in Japan and the United States.
How the Flaw Works
CVE-2026-61500 stems from how Rejetto HFS versions 3.0.0 through 3.2.0 generate session-cookie signing keys. The server relies on the non-cryptographic Math.random() function, using the xorshift128+ algorithm, to produce values later passed to the Node.js framework Koa for cookie signing. Because xorshift128+ outputs are mathematically reversible, an attacker who collects a handful of login responses can reconstruct the generator’s internal state and recover the signing key.
With a forged administrator cookie in hand, an attacker gains full administrative access to the server and can trigger remote code execution through HFS’s built-in server_code configuration feature, which allows execution of custom server-side JavaScript.
Discovered Using AI
The vulnerability was identified by researchers at Horizon3 using Anthropic’s Mythos AI model. According to Horizon3, Mythos did not just flag the insecure pseudo-random number generator in isolation, it also recognized that the application separately leaked raw Math.random() outputs during login, and connected the two issues into a viable exploitation chain. Horizon3 discovered the weakness in June and published a proof-of-concept exploit on September 30, 2026.
Patch Status and Recommendations
Rejetto addressed the flaw in version 3.2.1, released July 13, 2026, after the vendor acknowledged that multiple vulnerabilities could allow attackers to gain administrative access to HFS. VulnCheck has not observed confirmed successful exploitation or post-compromise activity tied to the recent scanning, but warns that possible outcomes include file theft or deletion, malware installation, or use of a compromised HFS server as a foothold into internal networks.
Administrators running Rejetto HFS are strongly urged to update to version 3.2.1 at minimum, or ideally the latest stable release, 3.3.4, without delay.
