As reported by The Hacker News, active exploitation of CVE-2026-61500 in Rejetto HTTP File Server (HFS) confirms a pattern we've tracked closely: legacy or niche web server software with weak cryptographic primitives becomes a soft target once a public PoC drops. The vulnerability is a textbook example of how a single flawed design decision — using Math.random() instead of a CSPRNG — cascades into full administrative compromise and remote code execution.
Vulnerability Overview
| CVE ID | CVE-2026-61500 |
|---|---|
| CVSS Score | 9.3 (Critical) |
| Affected Versions | Rejetto HFS 3.0.0 through 3.2.0 |
| Patched Version | 3.2.1 (released July 2026) |
| Root Cause | Session-cookie signing key derived from non-cryptographic Math.random() PRNG; generator outputs disclosed to unauthenticated clients during SRP login handshake |
| Attack Chain | Collect login responses → reconstruct V8 PRNG state → recover signing key → forge admin session cookie → execute arbitrary JavaScript via server_code configuration → RCE |
| Active Exploitation | Confirmed — reconnaissance probing from China Telecom IP targeting U.S. and Japan hosts (October 1, 2026) |
| Public PoC | Yes — Python-based exploit released by Alejandro Ramos (aramosf), late September 2026 |
Why This Matters
The vulnerability is notable not just for its severity but for the speed of the exploitation lifecycle. The patch shipped in July 2026, but it took only until late September for a public PoC to appear, and within 48 hours of Horizon3.ai's technical writeup, in-the-wild probing began. This is the modern exploit economy: detailed research disclosures effectively serve as operational blueprints for threat actors who scan for unpatched instances within hours.
Rejetto HFS is often deployed in ad-hoc or semi-managed environments — file sharing servers, internal tooling, lab environments — where patch hygiene is inconsistent. These deployments frequently sit on network edges with minimal monitoring, making them ideal footholds for lateral movement or as command-and-control infrastructure.
The core lesson here is architectural:
Math.random()is not a cryptographic primitive. Any session token, signing key, or authentication secret that derives entropy from a non-CSPRNG is a vulnerability waiting to be discovered — and AI-assisted vulnerability research is dramatically compressing the timeline between flaw and exploit.
Who Is Most at Risk
Shield53 Recommendations
Immediate Actions
- Patch now: Upgrade to Rejetto HFS 3.2.1 or later. If you cannot patch immediately, take the instance offline or restrict access via allowlist at the network layer.
- Inventory and identify: Scan your external and internal attack surface for any HFS instances. Tools like Shodan, Censys, or internal asset discovery can identify hosts running HFS on default or non-standard ports.
- Hunt for compromise: If HFS was running unpatched since July 2026, review server logs for anomalous
server_codeconfiguration changes, unexpected JavaScript execution, new user accounts, or outbound connections to unfamiliar IPs. Look for signs of post-exploitation: modified binaries, scheduled tasks, or reverse shells. - Network segmentation: Ensure any remaining HFS instances are isolated from critical infrastructure. HFS should not be co-located with domain controllers, databases, or management networks.
- Block and monitor: If you have NGFW or IDS capabilities, add detection rules for the known PoC patterns — specifically, repeated unauthenticated SRP login attempts followed by requests to administrative API endpoints. Monitor for China Telecom IP ranges if your threat model warrants geographic blocking.
Broader Defensive Posture
- Audit cryptographic choices in any self-hosted or third-party web applications your organization maintains. Any use of
Math.random(),time()-based seeds, or similar weak entropy sources for security-sensitive operations is a critical finding. - Accelerate patching SLAs for critical CVSS (9.0+) vulnerabilities. The window between patch availability and active exploitation is shrinking — in this case, to roughly two months, and the PoC-to-exploitation gap was under 48 hours.
- Prepare for AI-assisted vuln discovery: The fact that Anthropic's Mythos model was used to discover this flaw signals a shift. Organizations should expect vulnerability disclosure velocity to increase and plan their patch management and threat intelligence programs accordingly.