Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to unauthenticated admin access and RCE (CVE-2026-61500) under active exploitation
Rejetto HTTP File Server (HFS) 3.x session forgery via (TL-2026-2865), also tracked as Rejetto HFS session forgery via predictable signing key, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-10-03. It is linked to a China-nexus actor with low confidence, affects Rejetto HTTP File Server (HFS), references 1 CVE (CVE-2026-61500), maps to 6 MITRE ATT&CK techniques (T1059.007, T1087, T1090), and is covered by 9 detection rules and 7 indicators of compromise.
Key facts for TL-2026-2865
- Threat ID
- TL-2026-2865
- Also known as
- Rejetto HFS session forgery via predictable signing key
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-10-03
- Last reviewed
- 2026-10-03
- Attribution confidence
- LOW
- Nation-state nexus
- China
- Motivation
- UNKNOWN
- Target regions
- united states of america, japan
- Detection rules
- 9
- Indicators of compromise
- 7
Malware and tooling in Rejetto HTTP File Server (HFS) 3.x session forgery via
Malware and tooling: Z3 SMT solver
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and leaks outputs of the same generator to unauthenticated clients, letting a remote attacker recover the PRNG state, forge an administrator session cookie and execute code via the server_code feature. VulnCheck canaries observed exploitation attempts from a China-based IP against real vulnerable hosts in the US and Japan, followed by activity from two US-based IPs in the same /24.
How Rejetto HTTP File Server (HFS) 3.x session forgery via works
CVE-2026-61500 affects the TypeScript rewrite of Rejetto HTTP File Server (HFS), versions 3.0.0 through 3.2.0. HFS generates the key used to sign session cookies (via the Koa web framework's keygrip) with JavaScript's Math.random(). V8 implements Math.random() with xorshift128+, a non-cryptographic generator whose internal state is fully reversible. HFS additionally discloses raw Math.random() outputs to unauthenticated clients during login, so an attacker has the observations needed to reconstruct the generator state.
Per Horizon3.ai's write-up and The Register's summary, the exploit chain is: (1) user enumeration to confirm that an admin account exists; (2) collect roughly 12 consecutive Math.random() outputs from the unauthenticated endpoint that leaks them; (3) use the Z3 SMT solver to recover the xorshift128+ internal state; (4) step the state backwards to reconstruct the signing key generated at server startup; (5) forge a valid administrator session cookie (session IP binding could also be bypassed through forged cookie parameters); (6) abuse built-in administrative functionality, namely the server_code configuration feature that accepts custom JavaScript, to run arbitrary code on the host. No prior authentication is required against an internet-reachable instance.
The flaw was discovered by Zach Hanley of Horizon3.ai working with Anthropic's Mythos model (Project Glasswing). It is tracked as CWE-338. The CVE record was published by VulnCheck on 2026-07-13, coinciding with HFS 3.2.1, whose release notes state that multiple security vulnerabilities in all previous versions could allow an attacker to gain administrative access. Horizon3's technical disclosure followed in late September 2026. CVSS is 9.8 (CVSS 3.1, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) per OpenCVE, and 9.3 (CVSS 4.0) as assigned by the CNA, VulnCheck. Sources report different scores for the same flaw.
According to The Register, VulnCheck's Patrick Garrity said VulnCheck began detecting exploitation of CVE-2026-61500 on the evening of the story, and that canaries saw an actor in China targeting real vulnerable hosts in the US. Targeting of hosts in the US and Japan was reported. Two US-based IPs, 173.239.211.248 and 173.239.211.249 in the same subnet, were reported as follow-on attackers and are suspected to be proxies. The reporting calls the activity China-nexus without naming a group, and notes it is consistent with the documented use of compromised devices as routing proxies in an April 2026 multi-country advisory. The CVE is listed in VulnCheck's KEV database. CraftedSignal's brief records it as not on CISA KEV. The Register cites Patrick Garrity's tracker as showing it is only the second Mythos/Project Glasswing-credited CVE exploited in the wild, out of 286 tracked.
BeaconBeagle returned no record (HTTP 404) for either reported IP at time of research, so no C2 correlation is available.
MITRE ATT&CK techniques used in TL-2026-2865
Execution
Discovery
Command and Control
Initial Access
T1190 Exploit Public-Facing Application
lateral-movement
Credential Access
Affected products and versions in Rejetto HTTP File Server (HFS) 3.x session forgery via
- Rejetto — HTTP File Server (HFS)
Vulnerable versions: 3.0.0 through 3.2.0
Fixed in: 3.2.1
Remediation for Rejetto HTTP File Server (HFS) 3.x session forgery via
Patches
- Rejetto HFS 3.2.1 (https://github.com/rejetto/hfs/releases/tag/v3.2.1)
Immediate actions
- Upgrade all Rejetto HFS instances to 3.2.1 or later
- Inventory HFS deployments and identify which are reachable from the internet; prioritise those for patching
- On any exposed pre-3.2.1 instance, review the server_code configuration and administrator accounts for unexpected changes
- Review web and authentication logs for repeated unauthenticated login requests and user enumeration from a single source
Workarounds
- Remove internet exposure of vulnerable instances until patched
Longer-term hardening
- Do not expose HFS administration to the internet; restrict access by network ACL or VPN
- Use cryptographically secure randomness (for example Node.js crypto.randomBytes()) for any security-sensitive value, never Math.random()
CVEs associated with Rejetto HTTP File Server (HFS) 3.x session forgery via
CVE-2026-61500
Weaknesses (CWE) in Rejetto HTTP File Server (HFS) 3.x session forgery via
CWE-338
Timeline of Rejetto HTTP File Server (HFS) 3.x session forgery via
- Rejetto releases HFS 3.2.1, noting multiple security vulnerabilities in all previous versions that could allow administrative access; VulnCheck publishes the CVE-2026-61500 advisory the same day.
- Zach Hanley of Horizon3.ai, working with Anthropic's Mythos model under Project Glasswing, identifies the Math.random()/xorshift128+ session-key weakness (Horizon3 dates discovery to September 2026; exact day not given).
- Horizon3.ai publishes its technical disclosure of the HFS session forgery to RCE chain (publication date as given on the Horizon3 page; The Register describes the publication as 'Wednesday').
- The Register reports CVE-2026-61500 as the second Mythos/Project Glasswing-credited CVE (of 286 tracked) exploited in the wild.
- The Register reports further exploitation from two US-based IPs in the same subnet (173.239.211.248 and 173.239.211.249), suspected to be proxies.
- VulnCheck reports its canaries detected a China-based IP exploiting CVE-2026-61500 against real vulnerable hosts in the US; targeting of hosts in the US and Japan is reported.
Sources cited for Rejetto HTTP File Server (HFS) 3.x session forgery via
- The Register: Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
- Horizon3.ai disclosure: Anthropic Mythos Rejetto HFS RCE
- VulnCheck advisory: Rejetto HFS session forgery via predictable signing key
- Rejetto HFS v3.2.1 release notes
- NVD: CVE-2026-61500
- OpenCVE: CVE-2026-61500
- Halo Security CVE advisory: Rejetto HFS predictable session key allows RCE
- CraftedSignal brief: Rejetto HFS session key
- Patrick Garrity: Anthropic-Credited CVEs tracker
More in vulnerability
- Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw
- Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898, CVE-2026-12627)
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)
- GitLab AI Gateway critical RCE via prompt template sandbox escape (CVE-2026-90970)
- CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD
Detection coverage for TL-2026-2865
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2865 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.