VulnCheck: First attack attempts against AI-discovered Rejetto HFS vulnerability

Just around one day after Horizon3 published a technical walkthrough of the AI-discovered vulnerability CVE-2026-61500 in Rejetto HFS, VulnCheck has recorded the first exploitation attempts.

AI-generated illustration: a black steel server cabinet with a hairline crack and an open drawer beside a stopwatch, symbolizing how quickly attackers exploit a newly disclosed file-server vulnerability.
Illustration
Gift article

VulnCheck: First attack attempts against AI-discovered Rejetto HFS vulnerability

Just around one day after Horizon3 published a technical walkthrough of the AI-discovered vulnerability CVE-2026-61500 in Rejetto HFS, VulnCheck has recorded the first exploitation attempts. The activity is so far small – but the sequence from publication to reconnaissance scanning illustrates Horizon3's point: that AI-assisted vulnerability research can compress the time between public documentation and available attack tooling.

The vulnerability

CVE-2026-61500 is a critical vulnerability (CVSS 9.3) in Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0. According to an advisory cited by The Hacker News, the flaw stems from two conditions that reinforce each other:

  • The server derives the signing key for session cookies from Math.random(), a non-cryptographic random number generator.
  • The same generator leaks raw output to unauthenticated clients during login.

The combination allows an attacker to reconstruct the generator's internal state, forge a valid administrator cookie, and achieve remote code execution (RCE) via HFS's built-in server_code configuration feature. No authentication is required.

The attack chain step by step

Horizon3's researchers describe, according to Cyberpress, the following seven-step chain:

  1. Confirm that the built-in administrator account exists, via a separate user-enumeration vulnerability – which Mythos also found and which has been published.
  2. Sample the endpoint that leaks raw Math.random() values twelve times.
  3. Feed the values into Microsoft Research's Z3 SMT solver as constraints to reconstruct the state of the xorshift128+ generator.
  4. Step the state backward to rebuild the signing key generated at startup.
  5. Forge a valid administrator cookie.
  6. Verify that the cookie grants authentication.
  7. Use HFS's built-in functionality to execute commands on the server.

Horizon3 claims that Mythos not only flagged the weak PRNG in isolation but, according to Hanley's own walkthrough, identified the leak, recognized the two findings as a chain, and determined that the leak provided exactly the observations needed for state recovery – and then wrote a working proof of concept with Z3 without follow-up questions. This rests on Horizon3's own reporting, not independent verification.

The timeline – told honestly

It is tempting to call this "exploited in a day," but that is imprecise. Horizon3 discovered the flaw, according to SecurityWeek, as early as June 2026, and version 3.2.1 with the necessary patches was released on July 13, 2026 – when VulnCheck also published the CVE registration, according to MSN – almost three months before the scanning began. A Python-based proof of concept was published in late September by security researcher Alejandro Ramos (aramosf). The short interval applies only from Horizon3's technical walkthrough to the first recorded exploitation attempts.

According to The Hacker News, Horizon3's Zach Hanley published his walkthrough on September 30, while MSN and The Register date it to Wednesday, October 1, 2026 – a discrepancy that cannot be resolved based on the available sources. VulnCheck's Patrick Garrity wrote, according to The Register, on Thursday on LinkedIn that the company that same evening had begun detecting exploitation of CVE-2026-61500 in Rejetto HFS. SecurityWeek dated VulnCheck's warning to October 2.

The scope of activity so far

It is important not to overstate this. VulnCheck's vice president of research, Caitlin Condon, wrote in a LinkedIn post cited by The Hacker News that "the activity so far appears to be small-scale reconnaissance scanning, with a single China Telecom IP probing Canary deployments in Japan and the United States." No confirmed successful compromises have been reported, and VulnCheck attributes the activity only to an "unnamed threat actor in China" that has targeted vulnerable hosts in the United States.

Garrity told The Register that Thursday evening's activity came from a single IP address in China that hit servers in the United States and Japan, and that as of Friday he had seen four hits from two different sources – the Register article is cut off mid-sentence about the origin of the hits, so the details remain unclear. According to Garrity's tracker, Mythos and Project Glasswing had as of Friday produced 286 CVEs; until Thursday, only one of them had been exploited in real attacks. CVE-2026-61500 is thus in practice the second vulnerability from this program to reach the wild – but far from the first in Rejetto HFS: CVE-2024-23692 (CVSS 9.8) was already weaponized by multiple threat actors in July 2024.

What the vulnerability means for AI-assisted security research

Horizon3 joined Anthropic's Project Glasswing in July 2026 and uses Mythos in its vulnerability research pipelines. The company warns – and this is their analysis, not established fact – that cheaper automation will change which classes of vulnerabilities attackers can afford to exploit at scale, and that complex, less reliable bugs such as memory-safety bugs may become practical targets. They also point out that off-the-shelf toolkits with current models can find things in projects that have never undergone security review.

This case illustrates the point: a vulnerability requiring an understanding of a specific PRNG, a leak code path, and solver-based state recovery was not only discovered but chained together and proven exploitable – according to Horizon3 – by a language model with minimal human follow-up.

What defenders should do

Update to Rejetto HFS 3.2.1 or later. The vulnerability requires no authentication, and HFS instances exposed to the internet while running 3.2.0 or earlier should be treated as possible targets.

Sources: The Hacker News, SecurityWeek, Cyberpress, The Register, MSN

AIMag.no
AIMag.no
The AIMag.no editorial team covers artificial intelligence, tools, research, and regulation.

Get the best of AI MAG in your inbox

News, analysis, and ideas at the intersection of AI and society.