Overview
- CVE-2026-61500 is a high-severity bug in Rejetto HTTP File Server that allows attackers to forge administrator session cookies and gain remote code execution.
- The flaw stems from HFS using JavaScript's non-cryptographic Math.random() to derive its session signing key while also leaking PRNG outputs to unauthenticated clients, enabling reconstruction of the PRNG state and recovery of the key.
- Researchers at Horizon3.ai credited Anthropic's Mythos model with identifying the exploitable chain and detailed write-ups and a public Python proof-of-concept were published in late September and early October 2026.
- Security firms reported the first observed exploitation attempts on October 3, 2026, with scans hitting U.S. and Japan hosts from China-hosted IPs and later attempts routed through U.S. proxies.
- Operators must upgrade to HFS 3.2.1, audit any server_code or admin settings for unauthorized changes, and treat internet-reachable 3.0.0–3.2.0 instances as potentially compromised because public PoCs sharply raised attack risk.