News.Lavx.Hu Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours
Article Content
- •CVE-2026-61500 allows remote code execution via an authentication bypass in Rejetto HFS.
- •Exploitation of the vulnerability began within 24 hours of its disclosure.
- •Users must update to Rejetto HFS version 3.2.1 or later to protect against this flaw.
Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to China. The vulnerability arises from insecure handling of session authentication using JavaScript's Math.random(), which is reversible due to the xorshift128+ algorithm. This flaw enables attackers to forge valid session cookies and gain administrative access. Users are urged to update to version 3.2.1 or later to mitigate the risk. The software had previously been listed on CISA's Known Exploited Vulnerabilities catalog for a different issue in 2024.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Anthropic and CVE-2024-23692 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Rejetto HFS are affected?
How urgent is the update?
What is the nature of the exploit?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…