- VulnCheck said CVE-2026-61500 has a CVSS score of 9.3.
- VulnCheck said an attacker can forge administrator cookies and execute code through HFS’s server_code configuration feature.
- VulnCheck saw small-scale reconnaissance targeting the flaw on October 2.
Rejetto HFS users face a critical vulnerability that VulnCheck said could let an unauthenticated attacker bypass authentication, forge administrator session cookies and execute code on the server. VulnCheck said the flaw is tracked as CVE-2026-61500 and has a CVSS score of 9.3.
VulnCheck warned on October 2 that hackers had begun targeting the flaw in small-scale reconnaissance from a China Telecom IP. The attempts hit canaries in Japan and the United States.
HFS is an open-source project that lets users host and share files with other users. The product has previously appeared on CISA’s Known Exploited Vulnerabilities list for CVE-2024-23692, an unauthenticated template-injection flaw leading to remote code execution.
On this page
HFS leaks session-generator output during login
VulnCheck said the flaw exists because HFS discloses outputs from its non-cryptographic session-cookie generator to unauthenticated clients during login.
VulnCheck said that, using the recovered key, the attacker can forge valid administrator session cookies to gain elevated access to the server and RCE via the server_code configuration feature.
Horizon3.ai used Mythos to uncover CVE-2026-61500
Horizon3.ai published its report on Sep 30. Its researchers used Anthropic’s Mythos AI model to uncover the vulnerability.
Horizon3.ai described a proof-of-concept that implemented a Z3 solver and demonstrated arbitrary command execution. The researchers identified insecure pseudorandom-number generation and a way to leak other numbers from the same generator stream.
Rejetto said previous HFS versions had security vulnerabilities
Rejetto said all previous HFS versions contained multiple security vulnerabilities that could allow an attacker to gain administrative access to HFS.
Horizon3.ai said its researchers discovered the flaw using Anthropic’s Mythos AI model.
FAQ
What is CVE-2026-61500?
VulnCheck said it is a critical Rejetto HFS vulnerability with a CVSS score of 9.3. It could allow an attacker to bypass authentication, forge administrator cookies and execute code through the server_code configuration feature.
Can CVE-2026-61500 enable remote code execution?
VulnCheck said an attacker can use a recovered signing key to forge administrator session cookies and gain remote code execution through the server_code configuration feature.
Has CVE-2026-61500 been exploited?
VulnCheck warned on October 2 that hackers had begun targeting the flaw in small-scale reconnaissance, with attempts hitting canaries in Japan and the United States.
Who discovered the Rejetto HFS flaw?
Horizon3.ai said its researchers uncovered the flaw using Anthropic’s Mythos AI model. Horizon3.ai published its report on Sep 30.
How does CVE-2026-61500 work?
VulnCheck said the flaw exists because HFS discloses outputs of its non-cryptographic session-cookie generator to unauthenticated clients during login.
Sources
How we checked this story
| Claim | Source | Status |
|---|---|---|
| VulnCheck said threat actors are exploiting a critical Rejetto HTTP File Server vulnerability to bypass authentication and gain remote code execution. | VulnCheck, via SecurityWeek | Attributed |
| VulnCheck said the vulnerability exists because HFS discloses outputs from its non-cryptographic session-cookie generator to unauthenticated clients during login. | VulnCheck, via SecurityWeek | Attributed |
| VulnCheck said the vulnerability is tracked as CVE-2026-61500 and has a CVSS score of 9.3. | VulnCheck, via SecurityWeek | Attributed |
| Horizon3.ai said horizon3 researchers discovered the vulnerability using Anthropic’s Mythos AI model. | Horizon3.ai, via SecurityWeek | Attributed |
| Rejetto said all previous HFS versions contained multiple security vulnerabilities that could allow administrative access. | Rejetto, via GitHub | Attributed |
| HFS is an open-source project that lets users host and share files with other users. | Horizon3.ai | Confirmed |
| HFS previously appeared on CISA’s Known Exploited Vulnerabilities list for CVE-2024-23692, an unauthenticated template-injection flaw leading to remote code execution. | Horizon3.ai | Confirmed |
| VulnCheck warned on October 2 that hackers had begun targeting CVE-2026-61500 in small-scale reconnaissance from a China Telecom IP. | VulnCheck, via SecurityWeek | Attributed |
| VulnCheck said the reconnaissance attempts hit canaries in Japan and the United States. | VulnCheck, via SecurityWeek | Attributed |
| Mythos created a proof-of-concept exploit that implemented a Z3 solver and demonstrated arbitrary command execution. | Horizon3.ai | Confirmed |
| horizon3.ai published its report on Sep 30, 2026. | horizon3.ai | Confirmed |
Could not verify
- Whether exploitation progressed beyond small-scale reconnaissance is not established
- How many HFS installations are affected is not established
- Whether the reported reconnaissance successfully achieved remote code execution is not established
- Whether the flaw received any additional vendor remediation beyond HFS version 3.2.1 is not established



