Rejetto HFS CVE-2026-61500: AI-found bug exploited in a day
Rejetto HFS CVE-2026-61500 lets attackers forge an admin cookie and run code. Attacks began a day after details went public. Upgrade to 3.2.1 now.
A bug that an AI model helped find is now under attack. Rejetto HFS CVE-2026-61500 is a critical flaw in HTTP File Server 3.0.0 through 3.2.0. An attacker with no password can forge an administrator session and run code on the server. The Register reports that the bug was publicly detailed on Wednesday and that exploitation started Thursday evening. That is one day. If you run HFS to share files with customers or staff, upgrade to 3.2.1 tonight.
What actually happened
Per the VulnCheck advisory, HFS made its session-cookie signing key from JavaScript's Math.random(), which is not a cryptographic generator. HFS also leaked outputs of that same generator to unauthenticated users during login. An attacker collects a few login responses, rebuilds the generator state, recovers the signing key, and forges an admin cookie. From the admin panel, the server_code setting gives remote code execution. CVSS is 9.3. The fix is in HFS v3.2.1, and the advisory is dated July 13.
Credit goes to Zach Hanley of Horizon3.ai, working with Claude and Anthropic Research. The Register says Anthropic's Mythos model spotted both halves of the attack: the weak generator and the leak of its raw output. It then suggested using the Z3 solver to recover the generator seed.
On exploitation, The Register quotes VulnCheck researcher Patrick Garrity: the first attacks came from a China-hosted IP against servers in the US and Japan, then from two US addresses that look like a proxy.
Why it matters for your business
The patch gap is now one day. The fix existed for months. The attacks started when the write-up appeared. Your patch window used to be the time between disclosure and a working exploit. AI-assisted research makes the write-up and the exploit arrive almost together.
Small file servers are the forgotten box. HFS is a single binary that someone ran "just for a week" to send a client big files. It often sits on a public port with no owner and no update process. That is the exact machine attackers scan for.
Weak randomness is a pattern, not a one-off. If your own app uses Math.random() for tokens, reset codes, or session IDs, fix it. Use crypto.randomUUID() or crypto.getRandomValues(). AI models are now good at finding this class of bug, for attackers and for you.
Key takeaways
- CVE-2026-61500 affects Rejetto HFS 3.0.0 through 3.2.0; the fix is in 3.2.1
- An unauthenticated attacker can forge an admin cookie and get remote code execution
- Exploitation began about one day after the technical details went public
- Find every HFS instance, upgrade it, or take it off the internet
- Search your own code for Math.random() in tokens and session IDs
Not sure what is exposed on your network? We audit the forgotten servers and quick fixes that grow into risks, then replace them with file sharing and auth you own and can patch. See what we build, or ask us to look at your stack.
Sources: The Register, VulnCheck advisory, Rejetto HFS v3.2.1 release.
- #rejetto-hfs
- #cve-2026-61500
- #vulnerability
- #patch-management
- #ai-security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
TA419 faked an Anthropic exec to phish: MFA codes didn't help
Proofpoint says China-aligned TA419 impersonated an Anthropic employee and used browser-in-browser phishing to steal MFA codes and sessions. Move to passkeys.
Read itPixelLeak: AI coding agents leaked 13,000 screenshots to GitHub
PixelLeak: AI coding agents put 13,000+ internal screenshots from 300+ organizations in public GitHub repos. How it happened and the controls to set now.
Read it