Rejetto HFS flaw found by AI now exploited in the wild
Attackers have started going after a critical authentication bypass in Rejetto HTTP File Server (HFS), according to VulnCheck. The flaw can lead to remote code execution (RCE). Researchers found it with help from an AI model.
The vulnerability is tracked as CVE-2026-61500 and has a CVSS score of 9.3. It affects the open source file server in all versions before 3.2.1.
A predictable "random" number
The problem is in how HFS creates and protects its session cookies. During login, the server sends unauthenticated clients output from its session cookie generator. That generator is not cryptographically secure. HFS also uses the same generator to create the key that signs those session cookies.
