Aiweekly.Co Critical RCE Flaw in Rejetto HFS Exploited Within 24 Hours
Article Content
- •CVE-2026-61500 allows unauthenticated RCE in Rejetto HFS due to predictable session keys.
- •Exploitation was confirmed within 24 hours of the vulnerability's disclosure.
- •Affected versions are 3.0.0 to 3.2.0; users must upgrade to 3.2.1 or later.
A critical vulnerability, CVE-2026-61500, was discovered in Rejetto HTTP File Server (HFS) that allows unauthenticated remote code execution (RCE). The flaw is due to the use of Math.random() for session key generation, which is predictable and reversible. Horizon3's Mythos AI identified the vulnerability, and exploitation was observed starting October 1, 2026, with attacks originating from a China-based IP targeting servers in the US and Japan. The vulnerability affects HFS versions 3.0.0 through 3.2.0, and a patch has been released in version 3.2.1. This incident marks a rapid transition from AI-assisted discovery to real-world exploitation, with VulnCheck confirming the exploitation activity. The vulnerability was first disclosed on September 30, 2026, and is not listed in the CISA KEV catalog.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-61500 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of HFS are affected?
Is there a patch available?
How urgent is this issue?
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…