Skip to content
Critical RCE Flaw in Rejetto HFS Exploited Within 24 Hours

Critical RCE Flaw in Rejetto HFS Exploited Within 24 Hours

First seen 4 Oct 2026, 16:05 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 17:02 UTC
  • •CVE-2026-61500 allows unauthenticated RCE in Rejetto HFS due to predictable session keys.
  • •Exploitation was confirmed within 24 hours of the vulnerability's disclosure.
  • •Affected versions are 3.0.0 to 3.2.0; users must upgrade to 3.2.1 or later.

A critical vulnerability, CVE-2026-61500, was discovered in Rejetto HTTP File Server (HFS) that allows unauthenticated remote code execution (RCE). The flaw is due to the use of Math.random() for session key generation, which is predictable and reversible. Horizon3's Mythos AI identified the vulnerability, and exploitation was observed starting October 1, 2026, with attacks originating from a China-based IP targeting servers in the US and Japan. The vulnerability affects HFS versions 3.0.0 through 3.2.0, and a patch has been released in version 3.2.1. This incident marks a rapid transition from AI-assisted discovery to real-world exploitation, with VulnCheck confirming the exploitation activity. The vulnerability was first disclosed on September 30, 2026, and is not listed in the CISA KEV catalog.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-13
CVE-2026-61500 published
The vulnerability was officially published with a CVSS score of 9.3, indicating critical severity.
Aiweekly.Co
2026-09-30
Vulnerability disclosed
Horizon3 published details about the critical flaw in Rejetto HFS, enabling RCE.
X
2026-10-01
Active exploitation observed
VulnCheck's canaries detected exploitation attempts from a China-based IP targeting US and Japanese servers.
Aiweekly.Co
2026-10-03
Patch released
Rejetto released version 3.2.1 to address the critical vulnerability.
X

More articles in this cluster (2)

Following this threat?

Track CVE-2026-61500 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of HFS are affected?
Versions 3.0.0 through 3.2.0 of Rejetto HFS are affected by CVE-2026-61500.
Is there a patch available?
Yes, Rejetto has released version 3.2.1 to fix the vulnerability.
How urgent is this issue?
The vulnerability is being actively exploited, making it critical for affected users to update immediately.