Skip to content
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours

Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •CVE-2026-61500 allows remote code execution via an authentication bypass in Rejetto HFS.
  • •Exploitation of the vulnerability began within 24 hours of its disclosure.
  • •Users must update to Rejetto HFS version 3.2.1 or later to protect against this flaw.

Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to China. The vulnerability arises from insecure handling of session authentication using JavaScript's Math.random(), which is reversible due to the xorshift128+ algorithm. This flaw enables attackers to forge valid session cookies and gain administrative access. Users are urged to update to version 3.2.1 or later to mitigate the risk. The software had previously been listed on CISA's Known Exploited Vulnerabilities catalog for a different issue in 2024.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-05-31
CVE-2024-23692 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-13
CVE-2026-61500 published
CVE-2026-61500 was officially published, detailing a critical authentication bypass in Rejetto HFS.
Horizon3.Ai
2026-09-27
First public PoC released
The first proof-of-concept for CVE-2026-61500 was made public, demonstrating the exploit.
Horizon3.Ai
2026-09-28
Exploitation begins
Active exploitation of the vulnerability was detected, with attacks traced to China targeting the US and Japan.
News.Lavx.Hu

More articles in this cluster (2)

Following this threat?

Track Anthropic and CVE-2024-23692 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Rejetto HFS are affected?
Versions prior to 3.2.1 are affected by CVE-2026-61500 and should be updated immediately.
How urgent is the update?
The vulnerability is actively exploited, making immediate updates critical to prevent unauthorized access.
What is the nature of the exploit?
The exploit allows attackers to forge session cookies, bypassing authentication and gaining administrative access.