SECURITYWEEK reports a critical vulnerability in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500 with a CVSS score of 9.3. The flaw arises because HFS discloses outputs of its non-cryptographic session-cookie generator to unauthenticated clients during login, and the same generator is used to derive the session-cookie signing key.
Attackers can reconstruct the generator’s state from a small set of login responses, recover the signing key, forge valid administrator session cookies, and achieve remote code execution via the server_code configuration feature. In effect, malicious actors can bypass authentication and gain elevated access, including RCE.
Security researchers from Horizon3[.]ai identified the weakness, explaining that the generator used by Math[.]random() employed the xorshift128+ algorithm, whose outputs are reversible. Horizon3’s technical report notes that Mythos AI aided the discovery. The flaw was disclosed in June, and Rejetto released version 3.2.1 on 13 July with the patch.
VulnCheck subsequently warned on 2 October that attackers began targeted exploitation as part of small-scale reconnaissance, with activity originating from a China Telecom IP and hits observed at canaries in Japan and the United States. Users of HFS should apply the patch to 3.2.1 or later, and monitor for indicators of exploitation tied to CVE-2026-61500.