"Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login," according to an advisory for the flaw.
CVE-2026-61500: predictable PRNG leads to session forgery
The vulnerability tracked as CVE-2026-61500 (CVSS 9.3) stems from the use of a weak pseudo-random number generator in Rejetto HTTP File Server (HFS). The advisory states that the product derived its session-cookie signing key from the non-cryptographic JavaScript Math.random() generator, and that outputs of that same generator were disclosed to unauthenticated clients during the login process. An attacker who collects a small number of login responses can reconstruct the generator's internal state, recover the signing key, and forge a valid administrator session cookie.
Administrative API and server_code: the route to remote code execution
Once an attacker forges an administrator session cookie, the advisory and subsequent analysis describe a direct escalation to remote code execution. Horizon3.ai researcher Zach Hanley noted that Rejetto HFS's administrative API allows for custom endpoints that can execute arbitrary JavaScript. Hanley summarized the impact as an authentication bypass that facilitates arbitrary remote code execution on Rejetto HFS, and described the combination of predictable session keys and executable administrative endpoints as "a clear path from unauthenticated access to administrative control, and ultimately, remote code execution."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramblePatch and public proof-of-concept: July patch, September PoC, October exploitation
Rejetto released a patched build, version 3.2.1, in July 2026 to address the flaw. Despite the upstream fix, public details and exploit code followed months later. Horizon3.ai published a post on September 30, 2026 that included technical details and credited Anthropic's Mythos model with being used to discover the vulnerability. In late September a security researcher, Alejandro Ramos (aka aramosf), released a Python-based proof-of-concept (PoC) exploit demonstrating how to reconstruct the V8 PRNG state, recover the signing key, and forge an administrator session to use the documented server_code configuration feature to execute server-side JavaScript.
Observed exploitation and actor activity
VulnCheck reported exploitation attempts beginning October 1, 2026. Patrick Garrity of VulnCheck said the company detected activity a day after the Horizon3.ai post and identified an unnamed threat actor in China targeting real vulnerable hosts in the United States. The detected activity therefore follows the sequence of a published patch (July), public disclosure and PoC (late September), and observed attacks (October 1).
CVE-2026-61500 in context: the second Rejetto HFS vulnerability under active exploitation
CVE-2026-61500 is the second Rejetto HFS flaw observed being weaponized in the wild. The older issue, CVE-2024-23692 (CVSS 9.8), was exploited in July 2024 by multiple threat actors who weaponized the flaw to deliver cryptocurrency miners, trojans, and a malware family named HATVIBE. The new wave of activity places CVE-2026-61500 alongside that earlier incident as a recurring source of operational risk for exposed HFS instances.
What this means for technologists and security teams, policymakers, and affected enterprises
- Technologists and security teams: Confirm whether deployed HFS instances are running versions 3.0.0 through 3.2.0 and, where present, apply the July 2026 patch (version 3.2.1). The publication of a public Python PoC and the rapid detection of exploitation underscore the need to inventory exposed HFS endpoints and monitor for forged session activity.
- Policymakers and regulators: The reported activity links a detected campaign to an unnamed actor in China targeting U.S. hosts. Those facts may inform cross-border threat tracking and incident reporting considerations tied to widely used server software that exposes administrative APIs capable of executing code.
- Affected enterprises and procurement leaders: For organizations that still operate Rejetto HFS, the timeline — patch in July, public PoC in late September, exploitation observed on October 1 — is a clear signal to validate patching posture, remove or isolate exposed instances, and review configuration options such as server_code that enable server-side script execution.
The record in this case is stark: a non-cryptographic random generator produced predictable session keys, those keys allowed forged administrator cookies, and an administrative feature that runs arbitrary JavaScript converted authentication bypass into remote code execution. The cadence of events — patch, public PoC, then observed exploitation — highlights the narrow window between disclosure and active attacks. Whether remaining vulnerable hosts will be found and remediated, and how widely the PoC will be weaponized beyond the activity VulnCheck reported on October 1, are the concrete next steps the facts leave open.




