Both SecurityWeek and The Hacker News report active exploitation of CVE-2026-61500, a critical vulnerability in Rejetto HTTP File Server. The flaw allows an unauthenticated attacker to recover the session-cookie signing key, forge an administrator session, and achieve remote code execution.
The root cause is a weak pseudo-random number generator: Rejetto HFS versions 3.0.0 through 3.2.0 derive the signing key from JavaScript's Math.random() and expose outputs of the same generator during the login handshake. By collecting a small number of login responses, an attacker can reconstruct the generator's state and recover the key. The Hacker News notes the CVSS score is 9.3.
The vulnerability was discovered by Horizon3.ai researcher Zach Hanley using Anthropic's Mythos model, according to The Hacker News. A patch was released in July 2026 in version 3.2.1, but a public PoC only appeared in late September. VulnCheck detected exploitation on Oct 1, 2026, a day after additional technical details were published, and attributed the activity to an unnamed China-based threat actor targeting U.S. hosts. SecurityWeek's report focuses on the AI-assisted discovery and the exploitation, while The Hacker News provides the fuller timeline and technical detail.