Executive Summary
CVE-2026-61500 is a critical vulnerability (CVSS 9.3) affecting Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0. Discovered using Anthropic's Mythos AI through Project Glasswing, the flaw stems from the insecure use of JavaScript's `Math.random()` to generate session-signing secrets. By reconstructing the pseudo-random number generator (PRNG) state, attackers can forge valid administrator session cookies.
Technical analysis reveals a chain involving PRNG state recovery via unauthenticated information leakage, session forgery, and subsequent abuse of administrative APIs to execute arbitrary server-side JavaScript. This vulnerability moved from public disclosure by Horizon3.ai on September 30, 2026, to active exploitation in the wild by October 1, 2026.
Successful exploitation grants an attacker full host compromise. Organizations running affected versions are urged to upgrade to HFS 3.2.1 immediately, as typical remediation like password changes will not mitigate this session-forgery technique.
