Rejetto HFS flaw found by AI now exploited in the wild
Attackers have started going after a critical authentication bypass in Rejetto HTTP File Server (HFS), according to VulnCheck. The flaw can lead to remote code execution (RCE). Researchers found it with help from an AI model.
The vulnerability is tracked as CVE-2026-61500 and has a CVSS score of 9.3. It affects the open source file server in all versions before 3.2.1.
A predictable "random" number
The problem is in how HFS creates and protects its session cookies. During login, the server sends unauthenticated clients output from its session cookie generator. That generator is not cryptographically secure. HFS also uses the same generator to create the key that signs those session cookies.
An attacker can collect a small number of login responses and use them to rebuild the generator's internal state. From there, they can recover the signing key.
With the key, the attacker can forge session cookies that the server accepts as valid administrator sessions. This gives them elevated access. Once inside, they can reach remote code execution through the server_code configuration feature.
Horizon3 explained the issue in a technical report. HFS relied on JavaScript's Math.random() to produce a "random" value. That value was passed to Koa, the Node.js web framework the server uses, to sign session cookies. Math.random() uses the xorshift128+ algorithm, and its outputs can be reversed.
In practice, an attacker who collects enough Math.random() outputs can work out other numbers the generator produced. That includes the secret used to sign authentication cookies.
Spotted by Anthropic's Mythos
Horizon3.ai researchers found the weakness using Anthropic's Mythos AI model. The model used advanced mathematical reasoning to recognize that the pseudorandom number generator (PRNG) outputs from Math.random() could be reversed. It then showed how this could be used to reconstruct the secret session-cookie signing key.
Horizon3.ai found the flaw in June. Rejetto shipped HFS version 3.2.1 with fixes on July 13.
"Multiple security vulnerabilities have been found in all previous versions, potentially allowing an attacker to gain administrative access to HFS," Rejetto said in its advisory.
Reconnaissance from a China Telecom IP
On October 2, VulnCheck reported that threat actors had begun targeting CVE-2026-61500. The activity is small in scale and looks like reconnaissance. It came from an IP address belonging to China Telecom.
The attempts hit VulnCheck's canaries in Japan and the US. Canaries are decoy systems that security firms deploy to detect and record attack traffic.
VulnCheck's warning does not describe the full scope of the activity. It does show that someone is now actively probing HFS servers for the bug, almost three months after the patch was released.
Admins running HFS should confirm they are on version 3.2.1 or later. Rejetto says all earlier versions are affected by multiple vulnerabilities. Because this flaw can lead to full administrative control and code execution, any HFS instance reachable from the internet and not yet updated should be treated as exposed.
Our Take
This case brings together two trends that have been building for a while. AI models are getting better at finding subtle bugs. And the gap between disclosure and exploitation keeps shrinking. We have already looked at how AI is speeding up exploitation as disclosure numbers grow. CVE-2026-61500 is a concrete example of the first half of that story.
The bug itself is worth noting. Using a non-cryptographic PRNG for security-sensitive values is a well-known mistake. But spotting that Math.random() outputs leaked at login could be chained back to a signing key takes real mathematical insight. That a model flagged this suggests AI-assisted review may surface older, subtle weaknesses in widely used open source projects. Small projects may struggle to handle that volume. Google's decision to pause its OSS bug bounty over AI-generated reports shows the strain is already visible.
There is also an uncomfortable point here. Defenders found and fixed this flaw well before attacks began, which is a good result. But once details are public, the same reasoning is available to attackers too. Microsoft has warned that attackers currently lead defenders in the early AI race. Lightweight tools like HFS are often set up quickly and then forgotten, which makes them easy targets.
It is worth watching whether the reconnaissance VulnCheck saw grows into broader scanning and exploitation. It is also worth watching whether other projects that rely on Math.random() for secrets get similar scrutiny.
