CVE-2026-61500: Rejetto HFS Critical RCE Discovered by AI Model Under Active Exploitation

Rejetto HFS CVE-2026-61500 AI Discovered Zero-Day Vulnerability
📌
Security Roundup Series: Weekend of October 5, 2026 • 4 min read deep dive
🚨
Vulnerability Intelligence: CVE ID: CVE-2026-61500 (CWE-338 / CWE-287 / CWE-94) Severity: CRITICAL (CVSS 9.8) Status: Actively Exploited in the Wild (Initial attacks traced to Chinese IP infrastructure) Affected Systems: Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0 Fixed In: Rejetto HFS version 3.2.1

In a watershed moment highlighting the dual-use reality of autonomous artificial intelligence in offensive security, CVE-2026-61500 (CVSS 9.8) represents a critical Remote Code Execution flaw in Rejetto HTTP File Server (HFS) that was originally uncovered during automated vulnerability analysis utilizing Anthropic’s "Mythos" AI model. Over the October 3–5 weekend, global threat intelligence centers observed active exploitation of this exact flaw in the wild, with Chinese-origin threat groups targeting unpatched servers across enterprise networks in the US, Europe, and Japan.

Cryptanalytic Root Cause: PRNG Flaw & State Reconstruction

Rejetto HFS versions 3.0.0 through 3.2.0 are built upon a modern Node.js/TypeScript architecture. To generate session-cookie signing secrets and CSRF tokens, the software relied on JavaScript's standard pseudo-random number generator, Math.random(), rather than the cryptographically secure crypto.randomBytes() API.

In modern V8 engines, Math.random() is implemented using the xorshift128+ algorithm, which maintains a 128-bit internal state. The critical vulnerability arises because the server simultaneously discloses raw outputs of this identical PRNG sequence to unauthenticated clients during the HTTP login challenge handshake:

/* Vulnerable Session Management in Rejetto HFS v3.2.0 */
import { Context } from 'koa';

// FLAW 1: Non-cryptographic secret derivation
const sessionSecret = Array.from({ length: 32 }, () => 
    Math.floor(Math.random() * 36).toString(36)
).join('');

export async function loginChallenge(ctx: Context) {
    // FLAW 2: Leaking internal PRNG state to unauthenticated remote clients!
    const challengeToken = Math.random().toString(36).substring(2);
    ctx.set('X-HFS-Challenge', challengeToken);
    ctx.body = { status: 'ready', challenge: challengeToken };
}

Because the challenge tokens directly reveal successive floating-point outputs from the xorshift128+ state engine, an external attacker needs only to request 5 to 10 consecutive challenge tokens. Using linear equation solvers (such as Z3 or specialized xorshift solvers), the attacker can reconstruct the internal 128-bit PRNG seed with 100% mathematical certainty in under 200 milliseconds.

From Secret Recovery to Remote Code Execution

Once the PRNG seed is reconstructed, the attacker predicts the exact value generated for sessionSecret upon server startup. With this secret in hand, the attacker can forge a valid administrative session cookie (HFS_SESSION) with root privileges:

Exploit Sequence:
1. GET /api/v1/auth/challenge (x8 requests) -> Collect PRNG output stream
2. Reconstruct xorshift128+ internal state via mathematical solver
3. Derive server-side 'sessionSecret' HMAC key
4. Craft forged administrator session cookie:
   HFS_SESSION=admin.eyJ1c2VyIjoiYWRtaW4iLCJyb2xlIjoidXNlciJ9.[HMAC_SIGNATURE]
5. Authenticate to /api/v1/config/server_code
6. Inject arbitrary NodeJS payload -> Execute system commands via child_process.exec()

Detection Telemetry & Indicators of Compromise

Organizations hosting Rejetto HFS must immediately search HTTP access logs for high-frequency challenge generation followed by immediate configuration POSTs:

🔍
Elasticsearch / Splunk Detection Query:
index=web_proxy uri_path="/api/v1/auth/challenge" | stats count as challenge_requests, values(client_ip) as ip by session_id | where challenge_requests >= 5 | join ip [ search index=web_proxy uri_path="/api/v1/config*" http_method="POST" ]
🛡️
Suricata Intrusion Rule:
alert http $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"COLIBRISEC - Rejetto HFS CVE-2026-61500 Admin Config Code Injection Attempt"; flow:to_server,established; content:"POST"; http_method; content:"/api/v1/config"; http_uri; content:"server_code"; http_client_body; classtype:web-application-attack; sid:20260402; rev:1;)

Remediation Guidance

  • Immediate Upgrade: Update all Rejetto HFS instances to version 3.2.1 or later. The patch replaces Math.random() with crypto.randomBytes() and isolates session signing tokens.
  • Audit Network Exposure: Ensure file server administrative portals are not exposed directly to the public internet; enforce access through an authenticated reverse proxy or internal VPN.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther