MikhbarMIKHBAR
Cybersecurity

Rejetto HFS Vulnerability Discovered by AI Hit by Exploitation

Threat actors have begun exploiting a critical vulnerability in Rejetto HTTP File Server (HFS) that was originally uncovered using artificial intelligence. The flaw allows attackers to bypass authentication and achieve remote code execution.

Rejetto HFS Vulnerability Discovered by AI Hit by Exploitation

Active Exploitation Targets Rejetto HFS Flaw

Threat actors are actively exploiting a critical vulnerability in Rejetto HTTP File Server (HFS) to bypass authentication and gain remote code execution, as VulnCheck has warned. Tracked as CVE-2026-61500 with a CVSS score of 9.3, the flaw exists because the open-source file server discloses outputs of its non-cryptographic session cookie generator to unauthenticated clients during the login process.

On October 2, VulnCheck reported that hackers began targeting CVE-2026-61500 as part of small-scale reconnaissance originating from a China Telecom IP address. These scanning and targeting attempts successfully hit canaries set up in both Japan and the United States, signaling that malicious operators are actively probing for vulnerable systems.

AI-Driven Discovery Uncovers Cryptographic Weakness

The critical security flaw was originally uncovered by Horizon3.ai researchers using Anthropic’s Mythos AI model. According to the cybersecurity firm, the AI model applied advanced mathematical reasoning to recognize that the pseudo-random number generator outputs could be reversed to reconstruct secret signing keys.

Detailed insights into how the vulnerability functions were published by the security researchers. A comprehensive technical report explains the underlying mechanics of how the file server handles cryptographic operations during user authentication.

Technical Mechanics of CVE-2026-61500

The vulnerability stems from how Rejetto HFS derives its session-cookie signing key from the same non-cryptographic generator used for other outputs. The sensitive information leak allows an attacker to reconstruct the generator's internal state and recover the signing key by gathering a small set of collected login responses.

Specifically, the file server's generator, Math.random(), was utilizing the xorshift128+ algorithm to create the pseudo-random value passed to the Node.js web framework Koa for signing session cookies. Because the algorithm's outputs are completely reversible, an attacker capable of collecting other numbers generated by Math.random() can determine subsequent numbers and successfully forge valid authentication cookies.

Administrative Access and Remote Code Execution

Once an attacker successfully recovers the session-cookie signing key, they can forge valid administrator session cookies. This capability provides elevated access to the targeted server.

With elevated privileges secured, attackers can subsequently achieve remote code execution by leveraging the server_code configuration feature built into the file server framework. This exposes the underlying host environment to complete compromise.

Patch Availability and Vendor Response

Horizon3 discovered the vulnerability in June, prompting coordinated remediation efforts. Rejetto subsequently released version 3.2.1 of its HTTP File Server on July 13, incorporating the necessary security patches to resolve the flaw.

In its official advisory, Rejetto noted that multiple security vulnerabilities had been identified across all previous versions of the software. These older installations possess flaws that could potentially allow an unauthorized attacker to acquire full administrative control over the HFS instance, reinforcing the urgent need for administrators to upgrade their deployments immediately.

Sources

  • SecurityWeekExploitation Hits Rejetto HFS Vulnerability Discovered by AI

Continue chronologically

You are readingRejetto HFS Vulnerability Discovered by AI Hit by Exploitation
Citrix NetScaler Zero‑Day CVE‑2026‑88779 Exploited
Older storyCitrix NetScaler Zero‑Day CVE‑2026‑88779 ExploitedOctober 5, 2026 · 3 min

Related entity coverage