Attackers have begun scanning for Rejetto HFS servers affected by CVE-2026-61500, a flaw that lets an unauthenticated attacker forge administrator session cookies and reach remote code execution. VulnCheck detected the first scanning on October 5, five days after Horizon3 published technical details and a proof-of-concept exploit.
What CVE-2026-61500 Does in Rejetto HFS
CVE-2026-61500 affects Rejetto HFS versions 3.0.0 through 3.2.0. The server derives its session-cookie signing key from Math.random(), a non-cryptographic random number generator. Outputs from that generator are leaked to unauthenticated clients.
The source reports do not state a CVSS score for the flaw.
How Attackers Rebuild the Signing Key
Because the random values leak to anyone who connects, an attacker can collect them and rebuild the internal state of the generator. From that state the attacker can recover the key used to sign session cookies. With the key in hand, the attacker can forge an administrator cookie and log in as an administrator without credentials.
The forged administrator access leads to remote code execution. According to the reporting, the unauthenticated path to code execution makes file theft, malware installation and internal compromise possible on affected servers.
Anthropic’s Mythos Model and the Discovery Chain
Anthropic’s Mythos AI model reportedly identified the weak key generation and the information leak that together make the exploit chain work. The reporting describes the model as having found both the flaw in how the key is produced and the leak that exposes the values needed to reconstruct it.
Timeline of Disclosure and Scanning
Horizon3 published technical details and a proof-of-concept exploit on September 30, 2026. Scanning followed on October 5, when VulnCheck’s Canary honeypots recorded activity from a single China Telecom IP address.
The scanning was small in scale and consisted of reconnaissance. It targeted deployments in Japan and the United States.
VulnCheck Canary Honeypots Record the First Probes
VulnCheck runs Canary honeypots, which are decoy systems that imitate exposed services and log who connects to them. The October 5 probes against those decoys came from one IP address. The reporting does not describe successful compromises, only that scanning for vulnerable HFS instances has started.
A public proof-of-concept from Horizon3 predates the scanning by five days, and the reporting available so far describes reconnaissance only.
Fixed Versions and Affected Servers
Rejetto fixed the flaw in version 3.2.1. Users are advised to move to version 3.3.4. Servers on versions 3.0.0 through 3.2.0 remain exposed to the session-forgery path.
Why an Unauthenticated Path to Admin Matters on a File Server
HFS is a file-sharing server, and the flaw gives an unauthenticated remote attacker administrator-level control over it. An attacker with that control can steal the files the server holds, install malware, and use the compromised host as a base for movement into the internal network.
The leak of random values to unauthenticated clients is what removes any need for credentials. Anyone able to reach an exposed HFS instance can collect them.
The public proof-of-concept from Horizon3 and the first scanning from VulnCheck’s honeypots mark the start of attacker interest in CVE-2026-61500. Scanning so far has come from one IP address and has been limited to reconnaissance against deployments in Japan and the United States. Whether other actors join in will show in honeypot data over the coming days.
The affected range is narrow but explicit. Versions 3.0.0 through 3.2.0 carry the weak key generation, version 3.2.1 contains the fix, and the advised destination for users is 3.3.4. Administrators running an HFS server in that range can check the installed version against those numbers to establish whether the session-forgery path is open on their system.
