DEV Community

Cover image for Rejetto HFS CVE-2026-61500 exploited a day after write-up
techaiwire
techaiwire

Posted on Originally published at techaiwire.com

Rejetto HFS CVE-2026-61500 exploited a day after write-up

Attackers began exploiting CVE-2026-61500, a critical flaw in the Rejetto HFS file server, on October 3, 2026. That was one day after Horizon3.ai published how it works, The Register reports. The bug lets anyone forge an administrator login and then run code on the server. It was found with Mythos, Anthropic's vulnerability-hunting AI model, and HFS 3.2.1 fixes it.

What Rejetto HFS is and which versions are affected

HFS, short for HTTP File Server, is a free, open-source program that shares files from a computer through a web browser. Versions 3.0.0 through 3.2.0 are vulnerable, according to VulnCheck's advisory. Version 3.2.1 is the first fixed release.

The two main scores disagree slightly. VulnCheck rates the flaw 9.3 out of 10, while the Strix CVE database lists 9.8. Both put it in the critical band.

Detail Value
Affected versions HFS 3.0.0 through 3.2.0
Fixed version HFS 3.2.1
Severity score 9.3 (VulnCheck) or 9.8 (Strix)
CVE published July 13, 2026
Exploit details published October 2, 2026
First attacks seen October 3, 2026

How the attack works

The root cause is a random number generator that is not built for secrets. HFS creates the key that signs its login cookies with JavaScript's Math.random(). VulnCheck says HFS also "discloses outputs of the same generator to unauthenticated clients during login."

That pairing is the problem. In Google's V8 engine, which runs Node.js, Math.random() uses an algorithm called xorshift128+. It is fast but fully predictable. Anyone who sees enough of its outputs can work out its internal state, and then every number it will produce.

An attacker therefore starts login attempts and collects the leaked numbers. The Register says Horizon3 then used Z3, a tool that solves equations automatically, to rebuild the generator's state. From there, the attacker recovers the signing key and forges an administrator cookie.

"If an attacker can derive what the session signing key is, they can forge valid session cookies," Horizon3 researcher Zach Hanley told The Register. Admin access then leads to code execution through HFS's own server_code setting, VulnCheck says.

What Mythos found that a scanner might miss

Hanley credits Mythos with spotting the chain, not just the weak generator. Mythos noticed the insecure generator and the separate code path that leaked its outputs. It "recognized those two facts as a chain," Hanley told The Register. A tool that flags only Math.random() would report a weakness without proving it could be exploited.

Mythos is the invitation-only model Anthropic updated to Mythos 5.1 in September. It is credited with 286 CVEs as of October 3, The Register reports. The Register also counts this as the second Anthropic-linked flaw exploited in the wild since Horizon3 joined Project Glasswing, Anthropic's security program, in July 2026. VulnCheck credits the discovery to Hanley working with Anthropic Research.

Who is attacking

VulnCheck saw the first attacks on October 3 against servers in the US and Japan, coming from addresses hosted in China, The Register reports. Later attempts came through proxy servers in the US.

The timing shows how little a fix does on its own. The CVE record, which already pointed to the 3.2.1 fix, dates back to July 13. Yet at publication, the EPSS model, which estimates how likely a flaw is to be exploited within 30 days, put the odds at 0.75%, both VulnCheck and Strix say. The first attacks VulnCheck saw came only after a step-by-step write-up and a video existed.

What this means for developers

If you run HFS, upgrade to 3.2.1 now. Any server on 3.0.0 to 3.2.0 that is reachable from the internet should be treated as possibly compromised. Check its admin settings, especially server_code, for anything you did not add.

The wider lesson is for anyone writing JavaScript. Never use Math.random() for keys, tokens, session IDs or password resets. In Node.js, use crypto.randomBytes() or crypto.randomUUID(). In browsers, use crypto.getRandomValues(). Then search your own code for Math.random( near words like key, token, secret or session.

Also check what your app leaks. HFS was exploitable because it sent raw generator outputs to visitors who had not logged in. Random-looking IDs in error pages, login responses or headers can feed the same kind of attack.

Finally, do not wait for the exploit to patch. A low EPSS score measures attacker interest before a public write-up, not after one. AI tools like Mythos are now finding and explaining bugs faster, so the gap between a write-up and the first attack is likely to stay short.


This article was first published on Tech AI Wire.

Also available in

Deutsch · 日本語 · Français · Español · Português

Related on Tech AI Wire

Sources

Top comments (0)