Attackers Are Hunting a Rejetto HFS Flaw That an AI Model Found First
A session-cookie bug uncovered with Anthropic's Project Glasswing is now drawing live exploitation attempts against Rejetto's file server.

Key points
- CVE-2026-61500 carries a severity score of 9.3 out of 10 and affects Rejetto HFS versions 3.0.0 through 3.2.0.
- Horizon3 researchers working with Anthropic's Mythos AI model under Project Glasswing found the flaw before criminals began probing it.
- The bug lets an unauthenticated attacker forge the administrator's login cookie after watching a handful of normal login responses.
- Full admin access on HFS leads directly to remote code execution through the server's built-in scripting feature.
- Threat Vectr's own leak-site tracking hasn't yet seen a named ransomware crew claim an HFS-related victim, but exposed instances are a known target for opportunistic crews.
Someone is scanning the internet for Rejetto HFS, trying to break into servers that haven't been patched. What makes this one different is where the flaw came from: an AI model found it before any criminal did.
Rejetto HFS, short for HTTP File Server, is a small free program that lets a person share files from their own computer over the web. Hobbyists use it. So do small businesses that want a quick way to hand files to clients. Tens of thousands of instances sit exposed on the public internet at any one time.
What is the bug, in plain words?
The server hands users a login cookie, a small token the browser sends back to prove who you are. HFS was signing those cookies with a key generated by Math.random(), a function meant for things like shuffling cards in a browser game, not security work.
Worse, the server leaked other numbers from the same generator back to anyone who tried to log in. A patient attacker could collect a few of those numbers, work backwards to the generator's internal state, and recreate the signing key. From there they could mint a cookie that says "I am the admin" and the server would believe it.
Admin access on HFS isn't just admin access. The product has a feature called server_code that runs scripts on the host. Forge the cookie, drop in a script, and you're running commands on the machine. That's the remote code execution part of CVE-2026-61500.
Where did the AI angle come in?
Horizon3 disclosed the bug through Anthropic's Project Glasswing, a program that pairs an Anthropic model called Mythos with outside researchers to hunt flaws in widely used software. Horizon3 says Mythos is strong at the kind of long, patient reasoning this bug required: reading source code, spotting that the random-number generator was unsafe, then working out that its outputs leaked through the login flow. We first covered Project Glasswing on 28 May 2026 and have reported on it four times since.
Horizon3's writeup argues that AI assistance will shift which bug classes attackers find worth weaponising at scale. A flaw like this one, needing a chain of mathematical reasoning just to recognise, used to sit below the waterline. It's on a public advisory now, with a working exploit path.
Who is being attacked, and what should admins do?
VulnCheck, as first reported by The Hacker News, says it's seeing active exploitation attempts against exposed HFS servers. The company hasn't named victims. Threat Vectr's own tracking of ransomware leak sites hasn't linked a named crew to an HFS intrusion yet, but file servers sitting on the open internet are standard fare for smaller extortion gangs that trawl for easy wins.
| Item | Detail |
|---|---|
| CVE | CVE-2026-61500 |
| CVSS | 9.3 (critical) |
| Affected | Rejetto HFS 3.0.0 to 3.2.0 |
| Impact | Admin session forgery, remote code execution |
If you run HFS, update to a fixed build from Rejetto and, if you can, take the admin panel off the public internet entirely. Put it behind a VPN or an IP allow-list. For a tool this small, that's often the only honest answer.
Watch the broader pattern, not just this CVE. A model found a cryptographic weakness that would have taken a human researcher weeks of staring. Not every future discovery like this will be disclosed first.



