As reported by The Hacker News, active exploitation of CVE-2026-61500 in Rejetto HTTP File Server (HFS) confirms a pattern we've tracked closely: legacy or niche web server software with weak cryptographic primitives becomes a soft target once a public PoC drops. The vulnerability is a textbook example of how a single flawed design decision — using Math.random() instead of a CSPRNG — cascades into full administrative compromise and remote code execution.

Security Impact: As reported by The Hacker News, active exploitation of CVE-2026-61500 in Rejetto HTTP File Server (HFS) confirms a pattern we've tracked closely: legacy or niche web server software with weak cryptographic primitives becomes a soft target once a public PoC drops.

Vulnerability Overview

CVE IDCVE-2026-61500
CVSS Score9.3 (Critical)
Affected VersionsRejetto HFS 3.0.0 through 3.2.0
Patched Version3.2.1 (released July 2026)
Root CauseSession-cookie signing key derived from non-cryptographic Math.random() PRNG; generator outputs disclosed to unauthenticated clients during SRP login handshake
Attack ChainCollect login responses → reconstruct V8 PRNG state → recover signing key → forge admin session cookie → execute arbitrary JavaScript via server_code configuration → RCE
Active ExploitationConfirmed — reconnaissance probing from China Telecom IP targeting U.S. and Japan hosts (October 1, 2026)
Public PoCYes — Python-based exploit released by Alejandro Ramos (aramosf), late September 2026

Why This Matters

The vulnerability is notable not just for its severity but for the speed of the exploitation lifecycle. The patch shipped in July 2026, but it took only until late September for a public PoC to appear, and within 48 hours of Horizon3.ai's technical writeup, in-the-wild probing began. This is the modern exploit economy: detailed research disclosures effectively serve as operational blueprints for threat actors who scan for unpatched instances within hours.

Rejetto HFS is often deployed in ad-hoc or semi-managed environments — file sharing servers, internal tooling, lab environments — where patch hygiene is inconsistent. These deployments frequently sit on network edges with minimal monitoring, making them ideal footholds for lateral movement or as command-and-control infrastructure.

The core lesson here is architectural: Math.random() is not a cryptographic primitive. Any session token, signing key, or authentication secret that derives entropy from a non-CSPRNG is a vulnerability waiting to be discovered — and AI-assisted vulnerability research is dramatically compressing the timeline between flaw and exploit.

Who Is Most at Risk

Why This Matters
Organizations running Rejetto HFS 3.0.0–3.2.0 exposed to the internet, especially on cloud VPS instances
Internal file-sharing services that may be reachable via lateral movement from compromised endpoints
Environments lacking outbound EDR or network telemetry on non-standard ports where HFS is commonly hosted
SMBs and educational institutions that frequently use lightweight file server tools without dedicated security staff

Shield53 Recommendations

Immediate Actions

  • Patch now: Upgrade to Rejetto HFS 3.2.1 or later. If you cannot patch immediately, take the instance offline or restrict access via allowlist at the network layer.
  • Inventory and identify: Scan your external and internal attack surface for any HFS instances. Tools like Shodan, Censys, or internal asset discovery can identify hosts running HFS on default or non-standard ports.
  • Hunt for compromise: If HFS was running unpatched since July 2026, review server logs for anomalous server_code configuration changes, unexpected JavaScript execution, new user accounts, or outbound connections to unfamiliar IPs. Look for signs of post-exploitation: modified binaries, scheduled tasks, or reverse shells.
  • Network segmentation: Ensure any remaining HFS instances are isolated from critical infrastructure. HFS should not be co-located with domain controllers, databases, or management networks.
  • Block and monitor: If you have NGFW or IDS capabilities, add detection rules for the known PoC patterns — specifically, repeated unauthenticated SRP login attempts followed by requests to administrative API endpoints. Monitor for China Telecom IP ranges if your threat model warrants geographic blocking.

Broader Defensive Posture

  • Audit cryptographic choices in any self-hosted or third-party web applications your organization maintains. Any use of Math.random(), time()-based seeds, or similar weak entropy sources for security-sensitive operations is a critical finding.
  • Accelerate patching SLAs for critical CVSS (9.0+) vulnerabilities. The window between patch availability and active exploitation is shrinking — in this case, to roughly two months, and the PoC-to-exploitation gap was under 48 hours.
  • Prepare for AI-assisted vuln discovery: The fact that Anthropic's Mythos model was used to discover this flaw signals a shift. Organizations should expect vulnerability disclosure velocity to increase and plan their patch management and threat intelligence programs accordingly.