REJETTO HFS VULNERABILITY CVE-2026-61500 ACTIVELY EXPLOITED IN SERVER TAKEOVER ATTEMPTS

Attackers are exploiting a critical Rejetto HTTP File Server vulnerability that can allow remote users to gain administrative access and execute code without logging in. Tracked as CVE-2026-61500, the flaw affects HFS versions 3.0.0 through 3.2.0. VulnCheck began detecting exploitation activity through its canary infrastructure on October 1, 2026, and added the vulnerability to its Known Exploited Vulnerabilities database. The company identified approximately 100 internet-facing HFS instances, although that estimate does not establish how many servers are vulnerable or have been compromised.

The security weakness stems from HFS using JavaScript’s Math.random() function to generate the key that protects session cookies. Because this function is unsuitable for cryptographic security, attackers can use information exposed during login requests to recover the signing key and forge an administrator session. Administrative features can then enable server-side code execution, turning the authentication bypass into a potential server takeover. VulnCheck assigned the vulnerability a critical CVSS 4.0 score of 9.3, reflecting the risk of exploitation without credentials or user interaction.

Horizon3.ai researcher Zach Hanley discovered the vulnerability with assistance from Anthropic’s Mythos model through Project Glasswing. According to Horizon3.ai, the AI-assisted investigation connected predictable random-number generation, exposed outputs and privileged scripting functionality into a working attack chain. The research illustrates how AI can help investigators examine complex security weaknesses that previously required substantial specialist knowledge and development time. For defenders, the newly detected exploitation makes remediation an immediate priority rather than a routine response to an older disclosure.

Organizations should inventory their Rejetto HFS deployments and upgrade affected installations immediately. The vulnerability was addressed in HFS 3.2.1, while the official releases page currently lists 3.3.4 as the latest stable version. Administrators should also limit external access and investigate unexpected administrator sessions, configuration changes, unfamiliar processes and suspicious outbound connections. Servers showing evidence of compromise should be isolated for incident-response analysis, with accessible credentials and sensitive files treated as potentially exposed. Updating closes the vulnerability, but previously exposed systems still require investigation for signs of an earlier intrusion.

Leave a Comment

Your email address will not be published. Required fields are marked *