CVE-2026-61500
CVSS 9.8 CRITICAL: rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random()… EPSS 0.9% (57th percentile).
Vulnerabilities & Exploits
VulnCheck said CVE-2026-61500 in Rejetto HTTP File Server was being probed in the wild by Thursday, just a day after Horizon3’s Zach Hanley disclosed the flaw in the open source file server. The first activity came from a China-hosted IP and targeted vulnerable hosts in the US and Japan.
The bug is an authentication bypass: an attacker does not need a password to slip past the login gate, reach admin-level functions, and, in Hanley’s demonstration, turn that access into remote code execution on the server. That makes an exposed HFS instance more than a file share; it is a direct path to server control.
For operators running HFS on the internet, the exposure does not wait for a slower patch cycle. Once a bypass is public and already under attack, the remaining risk is every instance that still accepts traffic before v3.2.1 or later is in place.
1 source · 5h ago
CVSS 9.8 CRITICAL: rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random()… EPSS 0.9% (57th percentile).
The Register Security
Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
Exploitation attempts came from China-hosted IP, VulnCheck researcher says
originalPart of the PlainSec briefing for 2026-10-03
Every edition of this story: Rejetto HFS Auth Bypass Hit Within a Day