AI-found flaw in Rejetto HFS file server now under attack — update to 3.2.1
Anthropic's Mythos helped Horizon3.ai find a login-bypass flaw in HFS that leads to server takeover. Probing began a day after the write-up. Patch now.
An AI model found a critical login-bypass flaw in Rejetto HFS, a popular free file-sharing server, and attackers began probing for it about a day after the technical write-up appeared. Anyone running HFS 3.0.0 through 3.2.0 is affected. Update to 3.2.1 or later now, and take HFS off the public internet if you cannot.
What happened, in plain English
Rejetto HFS (HTTP File Server) is a small, free program that turns a computer into a web page for sharing files. It is often set up quickly — by a sysadmin, a developer or a lab team — to hand files to colleagues or customers, and then forgotten.
When you log in to HFS as an administrator, it gives your browser a "session cookie": a signed ticket that says "this person is the admin". The signature is made with a secret key that only the server should know.
The problem, tracked as CVE-2026-61500 (CVE is the public catalogue ID for a vulnerability), is that HFS created that secret key with a random-number function that is not designed for security. Worse, during the login process HFS also hands out other numbers from the same random-number generator to anyone who asks, no password needed. With enough of those numbers, an attacker can work backwards, recover the secret key and print their own valid admin ticket. Think of a ticket office whose "random" ticket numbers follow a hidden pattern, and which also posts its recent numbers in the window: collect enough of them and you can forge a VIP pass.
Admin access in HFS is enough to run code on the server, so the end result is a full takeover of the machine running HFS.
The flaw was found by Zach Hanley of the security firm Horizon3.ai using Anthropic's Mythos model, as part of Anthropic's Project Glasswing vulnerability-research programme. A fix was released on July 13, 2026. Horizon3 published its technical write-up dated September 30, 2026, and the vulnerability-intelligence company VulnCheck reported exploitation attempts against its sensors shortly after.
Are you affected? What to do now
You are affected if you run Rejetto HFS version 3.0.0 through 3.2.0. Versions 3.2.1 and later contain the fix. The CVE record does not list the older 2.x line as affected, but 2.x is a separate, older codebase that had its own critical flaw in 2024 (CVE-2024-23692) and should not be exposed either.
Checklist, in order:
- Find every HFS instance. Ask teams, check endpoint inventories and software-deployment tools for "HFS" or "hfs.exe", and look for small web servers on unusual ports. HFS is often installed on a desktop or a lab machine, not a managed server.
- Check the version. The version is shown in the HFS admin panel. Anything from 3.0.0 to 3.2.0 is vulnerable.
- Update to 3.2.1 or later from the official GitHub releases page. Download only from that page.
- If you cannot update today, remove internet exposure. Close the port at the firewall or router, disable UPnP port forwarding for HFS, or stop the service.
- Assume compromise if a vulnerable instance was reachable from the internet after September 30, 2026. Review the HFS admin settings for changes you did not make (especially custom server-side code), look for new accounts or unexpected files, and check the host for unfamiliar processes and outbound connections. If in doubt, rebuild the machine and change any credentials that were stored on it.
- After patching, restart HFS so a new signing key is generated, and log in again to confirm the version.
- Ask suppliers. If a vendor or contractor shares files with you through an HFS link, ask whether they have updated.
No official indicators of compromise (IOCs, such as attacker IP addresses) have been published by the vendor or a government agency. VulnCheck lists the flaw in its own Known Exploited Vulnerabilities (KEV) catalogue; at the time of writing we could not confirm that CISA, the US cybersecurity agency, has added it to its KEV list.
If you do not run HFS anywhere, there is nothing to do — but the "forgotten quick file server" pattern is worth a look in your next asset review.
The expert view
Conceptually, this is a classic bug class: CWE-338, use of a cryptographically weak pseudo-random number generator (PRNG). According to VulnCheck's advisory, HFS derives its session-cookie signing key from JavaScript's Math.random() and exposes outputs of the same generator to unauthenticated clients during login. Horizon3's write-up explains that the V8 engine's implementation of Math.random() (xorshift128+) is fast but reversible: given enough consecutive outputs, its internal state can be recovered with standard constraint-solving tools and then stepped backwards to the values used to build the key at process start. Forged admin cookie, then code execution through an admin configuration feature.
Neither half is new. Weak PRNGs and state-recovery attacks on xorshift128+ are well documented. What is notable is the chaining. Hanley writes that Mythos "did not require follow-on prompting to find the disparate PRNG leak that made this theoretical issue a demonstrable one", and that the model connected the weak key generation to a leak in a separate code path, then produced a working proof of concept. Horizon3 also argues that human researchers often skip this class of bug because proving exploitability takes mathematical work and time. That is the economic shift: findings that used to be dismissed as "theoretical" are now cheap to turn into demonstrated, critical bugs.
Some calibration is needed. Horizon3 is clear that humans still ran the harness and made the judgement calls; this was AI-assisted research, not an autonomous agent acting alone. And the exploitation reported so far is small: VulnCheck described early activity, which it saw on its canary sensors in the US and Japan, as small-scale and reconnaissance-like. No victim organisation has been named and no threat actor has been attributed by any source we read.
The more uncomfortable lesson is the timeline. The fix sat available for about eleven weeks, but the detailed write-up — not the patch — is what triggered attacks within roughly a day. Small, self-installed tools like HFS rarely have an update channel, an owner or an asset-inventory entry, so the patch-to-exploit gap is really a discovery gap. As AI-assisted research increases the number of well-documented, critical findings — Google's threat intelligence team recently reported that half the vulnerabilities AI finds allow code execution — defenders should expect more write-ups to arrive with a working chain attached, and should treat "detailed public write-up" as the real start of the exploitation clock.
For developers, the fix is simple and old: never use Math.random() or any general-purpose PRNG for keys, tokens or session identifiers; use the platform's cryptographic random generator. Code-review and static-analysis rules for CWE-338 are cheap to add.
Still unknown: how many vulnerable HFS servers are exposed online, whether any successful compromises have occurred, and who is behind the scanning.
Official sources
- Horizon3.ai — disclosure: Anthropic Mythos and Rejetto HFS RCE (CVE-2026-61500), September 30, 2026
- VulnCheck — advisory: Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key
- Rejetto HFS — v3.2.1 release notes (GitHub)
- Coverage: The Register — Anthropic's Mythos is good at math, as latest vuln under attack shows (October 3, 2026)
- Coverage: SecurityWeek — Exploitation Hits Rejetto HFS Vulnerability Discovered by AI (October 5, 2026)