Rejetto HFS CVE-2026-61500 exploited a day after write-up
Rejetto HFS CVE-2026-61500 Exploited One Day After Write-up
Overview
Attackers began exploiting CVE-2026-61500, a critical flaw in the Rejetto HFS file server, on October 3, 2026. This occurred one day after Horizon3.ai published how the vulnerability works, according to The Register. The bug allows anyone to forge an administrator login and then execute code on the server. It was discovered using Mythos, Anthropic's vulnerability-hunting AI model, and HFS 3.2.1 provides the fix.
What Is Rejetto HFS and Which Versions Are Affected?
Rejetto HFS (short for HTTP File Server) is a free, open-source program that shares files from a computer through a web browser. According to VulnCheck's advisory, versions 3.0.0 through 3.2.0 are vulnerable. Version 3.2.1 is the first fixed release.
| Detail | Value |
|---|---|
| Affected versions | HFS 3.0.0 through 3.2.0 |
| Fixed version | HFS 3.2.1 |
| Severity score | 9.3 (VulnCheck) or 9.8 (Strix) |
| CVE published | July 13, 2026 |
| Exploit details published | October 2, 2026 |
| First attacks seen | October 3, 2026 |
How the Attack Works
The root cause is a random number generator that is not designed for secrets. HFS creates the key that signs its login cookies using JavaScript's Math.random(). VulnCheck notes that HFS also "discloses outputs of the same generator to unauthenticated clients during login." This pairing is the core problem.
In Google's V8 engine (which powers Node.js), Math.random() uses an algorithm called xorshift128+. While fast, it is fully predictable. An attacker can start login attempts, collect leaked outputs, and then use a tool like Z3 (from The Register) to solve equations automatically and rebuild the generator's state. Once the signing key is recovered, the attacker can forge valid session cookies, leading to administrator access and ultimately code execution through HFS's server_code setting.
A tool that flags only Math.random() would report a weakness without proving it could be exploited. Mythos recognized the chain of issues - the insecure generator combined with the separate code path that leaked its outputs - rather than just reporting the weak generator itself.
Discovery and Mitigation
Mythos (Anthropic's invitation-only model updated to Mythos 5.1 in September) spotted the chain of vulnerabilities. It was credited with 286 CVEs as of October 3. The first attacks were observed on October 3 against servers in the US and Japan, originating from addresses hosted in China. Later attempts came through proxy servers in the US.
The EPSS model (which estimates how likely a flaw is to be exploited within 30 days) initially put the odds at 0.75% at publication. Despite the existing CVE record pointing to the 3.2.1 fix, the timing highlights how quickly exploitation can follow a write-up when AI-driven detection tools are involved.
Recommendations for Developers
If you run HFS, upgrade to 3.2.1 immediately. Any server running 3.0.0 to 3.2.0 that is reachable from the internet should be treated as potentially compromised. Review its admin settings, particularly server_code, for any changes you did not make.
For anyone writing JavaScript, the broader lesson is clear: never use Math.random() for keys, tokens, session IDs, or password resets. Instead:
- Node.js: Use
crypto.randomBytes()orcrypto.randomUUID() - Browsers: Use
crypto.getRandomValues()
Additionally, search your own codebase for occurrences of Math.random() near terms like key, token, secret, or session. Also verify whether your application leaks raw generator outputs in error pages, login responses, or headers - these can feed the same type of attack.
Finally, do not wait for the exploit to patch. A low EPSS score indicates high attacker interest even before a public write-up. AI tools like Mythos are accelerating the discovery of vulnerabilities, meaning the gap between a write-up and the first attack is likely to remain narrow.
Comments
No comments yet. Start the discussion.