Image: securityweek.com · rights & removal
Exploitation Hits Rejetto HFS Vulnerability Discovered by AI
Reporting by SecurityWeekRead the original at securityweek.com
Executive Summary
Facts Only
* Threat actors exploit a vulnerability in Rejetto HTTP File Server (HFS) to achieve remote code execution (RCE).
* The flaw is tracked as CVE-2026-61500 with a CVSS score of 9.3.
* The flaw exists because the open source file server discloses outputs from its non-cryptographic session cookie generator during login.
* The file server also derives the session-cookie signing key from this generator.
* Sensitive information disclosure allows an attacker to reconstruct the generator’s state and recover the signing key using collected login responses.
* The session cookie signing was generated using Math.random() employing the xorshift128+ algorithm.
* Recovering the signing key allows forging valid administrator session cookies, leading to elevated access and RCE via servercode configuration.
* Researchers utilized the Anthropic’s Mythos AI model to reverse the PRNG outputs and reconstruct the secret signing key.
* Rejetto HFS version 3.2.1 was released on July 13 with patches.
* Hackers began targeting CVE-2026-61500 starting October 2, originating from a China Telecom IP.
Full Take
The mechanism demonstrates a critical failure in the reliance on seemingly standard cryptographic primitives when implemented within complex systems. The root cause lies in treating a pseudo-random number generator (PRNG) output—Math.random() combined with xorshift128+—as an opaque source of entropy, rather than understanding its deterministic nature when used for session state management. This illustrates how complexity, combined with poor implementation choices in custom cryptographic routines, creates exploitable pathways that bypass traditional security controls. The discovery involved advanced mathematical reasoning, suggesting that the vulnerability was not easily found by standard vulnerability scanning but required deep analytical insight into the underlying mathematical functions.
The pattern here suggests a recurring theme where the gap between theoretical cryptographic concepts and their practical, implemented execution is exploited. Attackers leverage the reversibility of mathematical operations rather than brute force to achieve privilege escalation. The subsequent targeting from specific geographic IPs hints at a state-sponsored or highly organized reconnaissance effort, suggesting that high-severity vulnerabilities are being actively sought by actors with significant resources. This points toward a systemic challenge: developers must not only understand what algorithms they use but also the implications of their deterministic outputs in stateful systems.
What if all systems relied on truly unpredictable, cryptographically secure random number generators for session management, eliminating the possibility of deriving secrets from observable outputs? How does the reliance on open-source implementations introduce this level of systemic risk that requires specialized AI analysis to uncover? What are the implications for establishing trust in software that claims security through standard functions?
From the original · SecurityWeek
Threat actors are exploiting a critical vulnerability in Rejetto HTTP File Server (HFS) to bypass authentication and gain remote code execution (RCE), VulnCheck warns. Tracked as CVE-2026-61500 (CVSS score of 9.3), the flaw exists because the open source file server discloses outputs of its non-cryptographic session cookie generator to unauthenticated clients during login.Read the full story at securityweek.com
Sentinel — Likely Human
The text presents detailed technical findings regarding a specific software vulnerability and its exploitation, strongly suggesting it is based on real-world security research reported by named entities.
