ProBackend
active vulnerability exploitation
1 hour ago5 min read

Active Scanning Targets Rejetto HFS Over Critical Flaw Amid AI Cybersecurity Threats

Comprehensive analysis of the Rejetto HFS CVE-2026-61500 vulnerability, active scanning campaigns, and defensive remediation in the context of modern AI cybersecurity threats.

In the evolving landscape of enterprise security, the intersection of legacy application architecture and modern automated reconnaissance has created new vectors for attack. Recent telemetry from threat intelligence platforms reveals that malicious actors are actively scanning internet-facing instances of Rejetto HTTP File Server (HFS) for a critical remote code execution vulnerability, tracked as CVE-2026-61500. With a CVSS severity score reaching 9.3 to 9.8, this vulnerability highlights how minor cryptographic misconfigurations can snowball into full administrative compromise, especially as automated tooling and ai cybersecurity threats accelerate the speed of exploitation.

Rejetto HFS is widely deployed across Windows, Linux, and macOS environments for lightweight, self-hosted file sharing. However, versions 3.0.0 through 3.2.0 contain a fundamental flaw in how session management and pseudo-random number generation are handled, turning routine login interactions into an administrative takeover pipeline.

Understanding CVE-2026-61500 and AI Cybersecurity Threats

The technical root of CVE-2026-61500 lies in the improper handling of cryptographic operations. Specifically, Rejetto HFS versions 3.0.0 through 3.2.0 derive their session-cookie signing key from JavaScript’s non-cryptographic Math.random() generator. Worse still, the application discloses raw outputs of this same PRNG to unauthenticated clients during the standard login handshake.

This architectural oversight allows a remote, unauthenticated attacker to harvest a small number of login responses, reconstruct the internal state of the random number generator, mathematically recover the signing key, and forge valid administrator session cookies. Once an attacker possesses a legitimate administrative session token, they can leverage HFS's built-in server_code configuration feature to execute arbitrary server-side JavaScript, achieving complete remote code execution (RCE) on the underlying host.

In the broader context of modern ai cybersecurity threats, vulnerabilities discovered and chained with the assistance of advanced artificial intelligence models represent a paradigm shift. Horizon3 researchers initially discovered this complex vulnerability chain using Anthropic's advanced AI models (such as the Mythos model). Rather than flagging an insecure PRNG in isolation, the AI system simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two distinct facts as an exploitable chain, and determined that the leak produced precisely the observations required to make state recovery feasible. This mirrors the pattern examined in our companion piece on securing agentic infrastructure against escalating AI cybersecurity threats: AI accelerates both the discovery of chained flaws and the defenses built to contain them.

Automated Reconnaissance and Active Scanning Campaigns

Following the public disclosure of technical details and proof-of-concept (PoC) exploits—published by Horizon3.ai on September 30, 2026—threat actors swiftly weaponized the vulnerability. Over the subsequent weekend, VulnCheck’s VP of Security Research Caitlin Condon reported via LinkedIn that Canary Intelligence honeypots had observed active reconnaissance probes targeting CVE-2026-61500.

Initial telemetry indicates that this activity represents small-scale, targeted reconnaissance originating from a single China Telecom IP address probing deployments located in Japan and the United States. While widespread destructive payloads or mass ransomware deployment have not yet been formally documented in connection with these specific scans, the velocity from disclosure to active scanning underscores the persistent threat posed by automated attacker infrastructure.

Security teams monitoring internet-facing assets must recognize that modern adversaries—bolstered by automated scanning frameworks and AI-driven reconnaissance engines—can weaponize complex vulnerability disclosures within days or even hours. The same rapid scanning-then-exploitation cycle was recently documented in the wp2shell WordPress RCE chain, another reminder that internet-wide probes against a fresh CVE are an early warning that exploitation has already begun.

Technical Architecture of the Session Forgery Attack

To fully appreciate the severity of CVE-2026-61500, defenders must examine the precise mechanics of the attack vector:

  1. Information Disclosure During Login: When an unauthenticated user interacts with the login endpoint, Rejetto HFS inadvertently exposes outputs derived from Math.random().
  2. PRNG State Reconstruction: Because JavaScript's Math.random() is notoriously non-cryptographic and predictable (often backed by algorithms like xorshift128+ or older PRNG implementations depending on the runtime engine), collecting a minimal sample of outputs enables attackers to determine the generator's internal state.
  3. Session Cookie Signing Key Recovery: With the PRNG state mapped, calculating future outputs becomes trivial, allowing the adversary to compute the exact signing key used for session cookies.
  4. Administrative Forgery and RCE: Armed with the valid signing key, the attacker crafts a forged administrative session cookie. Logging in with elevated privileges, they execute arbitrary code via the server_code feature, granting full control over the file server environment.

This multi-step chain demonstrates why traditional static code analysis often fails to catch complex logical vulnerabilities without advanced cross-file context reasoning—a capability increasingly harnessed by both offensive security researchers and malicious threat actors.

Defense, Remediation, and Cybersecurity Best Practices

Given the critical severity (CVSS 9.3-9.8) and confirmed active scanning, immediate remediation is imperative for any organization utilizing Rejetto HFS.

1. Immediate Patching and Upgrades

Administrators must upgrade vulnerable Rejetto HFS installations immediately. While version 3.2.1 introduced the primary fix by replacing insecure PRNG mechanisms, organizations should ideally deploy the latest stable release (version 3.3.4 or higher) to ensure comprehensive protection against subsequent regressions or related flaws.

2. Network Segmentation and Exposure Reduction

Self-hosted file sharing tools should never be exposed directly to the public internet unless strictly necessary. Organizations should enforce robust perimeter controls:

  • Restrict access to internal networks or require authentication via a secure VPN or Zero Trust Network Access (ZTNA) gateway.
  • Implement Web Application Firewall (WAF) rules to detect and block anomalous login request patterns or repeated session generation queries.

3. Comprehensive Incident Response and Log Analysis

Security operations centers (SOCs) should inspect historical web server logs for suspicious login patterns, unusual requests targeting the authentication endpoint, or unexpected modifications to server-side configuration scripts (server_code). Integrating threat intelligence feeds covering CVE-2026-61500 will help identify early-stage reconnaissance before full exploitation occurs.

By combining rigorous patch management, strict access controls, and a proactive stance against emerging ai cybersecurity threats, organizations can mitigate the risks posed by predictable cryptographic weaknesses and safeguard their critical file infrastructure against automated compromise.

understanding cve-- and ai cybersecurity threats

More blogs