What it is
CVE-2026-61500 is an unauthenticated vulnerability affecting Rejetto hfs. Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
Vulnerability report
Rejetto HFS < 3.2.1 Session Forgery Remote Code Execution
Rejetto / hfs · affected before 3.2.1
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-61500 is an unauthenticated vulnerability affecting Rejetto hfs. Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is high. Also confirmed by third-party sources.
Who is affected?
Rejetto / hfs affected before 3.2.1.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login.
A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
The Hacker News
A trusted third party reported exploitation.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| The Hacker News First | 2026-10-05 08:32 UTC |
| Security Affairs | 2026-10-05 19:21 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v4.0
Potential damage if exploited. Separate from whether attackers are using it.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
1.0%
Estimated chance of exploitation in the next 30 days. Previdian's warning comes from evidence, not this score.
Recent mention · The Hacker News
Ravie LakshmananOct 07, 2026Artificial Intelligence / Vulnerability Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as...
Read full advisoryCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Recent mention · The Hacker News
Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 FlawsThe Hacker News · 07 Oct 2026
Ravie LakshmananOct 07, 2026Artificial Intelligence / Vulnerability Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional 5,500 verified software vulnerabilities between April and October 2026 through open-source scanning efforts. "Of these verified...
Recent mention · BleepingComputer
Rejetto HFS servers now actively scanned for critical RCE flawBleepingComputer · 05 Oct 2026
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [...]
Recent mention · Security Affairs
Anthropic Mythos Found A Bug in Rejetto HFS. Attackers Are Now Exploiting It.Security Affairs · 05 Oct 2026
AI-assisted research uncovered a critical Rejetto HFS flaw that enables authentication bypass and remote code execution, now exploited in the wild. A Rejetto HFS vulnerability, tracked as CVE-2026-61500 (CVSS score of 9.3), discovered with the help of the Anthropic Mythos AI model is now being exploited in the wild, turning an interesting security research experiment […]
Recent mention · The Hacker News
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCEThe Hacker News · 05 Oct 2026
Ravie LakshmananOct 05, 2026Vulnerability / Web Security A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and seize control of affected systems. "Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic...
Recent mention · TheRegister
Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack showsTheRegister · 03 Oct 2026
Exploitation attempts came from China-hosted IP, VulnCheck researcher says
Recent mention · Horizon3.ai Attack Research
Horizon3’s Tales from the Trenches: Anthropic’s Mythos and Rejetto HFSHorizon3.ai Attack Research · 30 Sep 2026
Horizon3 researchers used Anthropic’s Mythos to uncover a chain of cryptographic weaknesses in Rejetto HFS, recover a predictable signing key, forge an admin session, and achieve remote code execution.
Timeline
19:21 UTC
Exploitation attested by an external source
08:32 UTC
High-confidence, third-party attested exploitation
17:21 UTC
Vulnerability disclosed publicly
15:43 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-61500
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-61500",
"confidence": "High",
"cvss_score": 9.3,
"cvss_estimated": false,
"epss_score": 0.00987,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}