Rejetto HFS CVE-2026-61500 — a Flaw Anthropic's Mythos AI Helped Find — Is Now Under In-the-Wild Exploitation: Weak PRNG Enables Admin Session Forgery and RCE
Rejetto HFS CVE-2026-61500 — a Flaw Anthropic's Mythos AI Helped Find — Is Now Under In-the-Wild Exploitation: Weak PRNG Enables Admin Session Forgery and RCE
A critical flaw in Rejetto HTTP File Server (HFS) that was discovered with the help of an AI model is now being targeted by attackers. VulnCheck reported October 2 that it detected exploitation attempts against CVE-2026-61500 (CVSS 9.3), a session forgery vulnerability affecting HFS 3.0.0 through 3.2.0. The root cause is a textbook cryptographic failure: "Rejetto HFS derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login" — outputs of the generator appear in the unauthenticated SRP login handshake. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie.
From there the impact is total: HFS's administrative API allows custom endpoints that execute arbitrary JavaScript through the documented server_code configuration feature, so a forged admin session means full administrative access and remote code execution. Under the hood, JavaScript's Math.random() runs the xorshift128+ algorithm, whose outputs are reversible — the "random" values were passed to the Koa web framework for signing session cookies, so anyone who can observe enough generator outputs can predict every other one, including the key.
The discovery story is what makes this flaw notable. Researchers at Horizon3.ai used Anthropic's Mythos model to find the weakness — Zach Hanley's September 30 write-up describes the model applying mathematical reasoning to recognize that the PRNG outputs could be reversed to reconstruct the signing key. The flaw was found in June and patched in HFS 3.2.1 on July 13; Rejetto's advisory notes "multiple security vulnerabilities have been found in all previous versions, potentially allowing an attacker to gain administrative access." In late September, security researcher Alejandro Ramos (aramosf) released a public Python proof-of-concept, and by October 1 — a day after Horizon3 published additional details — VulnCheck saw probing begin. Caitlin Condon of VulnCheck describes the activity so far as "small-scale reconnaissance only, with a single China Telecom IP probing Canary deployments in Japan and the United States."
This is the second Rejetto HFS flaw to come under active exploitation after CVE-2024-23692 (CVSS 9.8), which multiple threat actors weaponized in July 2024 to deliver cryptocurrency miners, trojans and the HATVIBE malware. The arc from AI-assisted discovery to weaponized exploitation took about three months — a concrete example of the AI-accelerated discovery cadence CISA flagged in its "Quality Era" framework for the CVE program, where finding bugs is getting faster than ever while patching still runs at human speed.
What Should You Do?
- Upgrade any HFS 3.0.0-3.2.0 instance to 3.2.1 or later immediately — or better, retire internet-facing HFS deployments entirely; file servers rarely need public exposure in 2026.
- Audit administrative sessions and custom endpoints: look for session cookies you don't recognize and
server_codeor custom-endpoint configurations you didn't add. - Rotate anything the box could reach — credentials in scripts, shares, and connected services — if it was exposed with admin access possible.
- Treat every session system built on
Math.random()or any non-cryptographic PRNG as broken by design. This class of flaw is bigger than HFS; audit your own apps for where "random" values touch security decisions.
The WAF Angle
Here is the part that should humble edge-security tooling: a forged session cookie from this attack is structurally indistinguishable from a real one. The attacker doesn't send attack syntax — they observe legitimate login responses, do math offline, and then present a perfectly valid admin cookie. No signature, rule, or anomaly model that inspects requests will catch the moment of authentication, because the request is correct in every byte. What actually defends against this class: keeping admin interfaces off the internet, short session lifetimes, re-authentication for sensitive actions, and alerting when privileged sessions exercise dangerous features like server_code. The deeper lesson for web admins is that token predictability is an application flaw no WAF can patch at the perimeter — cryptographic randomness for anything security-relevant is table stakes, and the way this bug was found (by an AI model doing math on observable outputs) tells you the era of "too obscure to exploit" randomness bugs is over.