A vulnerability found with the help of an AI model went from public technical write-up to real-world exploitation in about a day. The flaw, CVE-2026-61500, affects Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0 and carries a CVSS v3.1 score of 9.8. It is fixed in version 3.2.1 — which, notably, had been available since July.
HFS is a free tool people run to share files from a Windows or Linux machine over the web, which means it tends to live on forgotten boxes with no owner and no update process. The bug chain starts with how HFS signs session cookies: the signing key is generated with JavaScript's Math.random(), which in the V8 engine is a fast but fully reversible xorshift128+ generator — not a cryptographic source of randomness.
What turns that weakness into a break is a second flaw. A separate code path leaks raw outputs of that same generator to anyone who hits the login flow. Zach Hanley, an attack engineer at Horizon3.ai, showed that an attacker who collects about a dozen of those leaked values can feed them to Z3, the open-source SMT solver, to recover the generator's internal state, rebuild the session-signing key, and forge a valid administrator cookie. No password is required; the attacker only needs one username that is allowed to log in. From the admin panel, HFS's server_code configuration option turns the bypass into full remote code execution.
The AI's contribution was specific. Horizon3 has used Anthropic's Mythos — a model Anthropic describes as too powerful for general release and provides to select partners through its Project Glasswing program, which Horizon3 joined in July — in its vulnerability research since then. Mythos spotted both halves of the chain: that the session key came from a reversible PRNG, and that the application leaked raw outputs of the same generator. It then suggested using Z3 for the state-recovery step, an application of an SMT solver to a cryptographic flaw that Hanley wrote he and his colleagues could not recall seeing before. The disclosure credits Hanley in coordination with Claude and Anthropic Research; the model worked inside a custom research harness, not as an autonomous end-to-end exploiter.
The timeline is the part security teams should internalize. VulnCheck assigned the CVE on July 13, with the fix already listed. Horizon3 published its detailed write-up on Wednesday, September 30. By Thursday evening, VulnCheck's canary honeypots were recording exploitation. The Register reported that the initial attacks came from a single IP address geolocated to China against vulnerable hosts in the United States and Japan, followed on Friday by two US addresses in the same subnet that VulnCheck believes were a proxy. VulnCheck has added the flaw to its known-exploited list and estimates roughly 100 HFS instances are exposed to the internet.
The broader numbers put the episode in context. VulnCheck's tracker credits Mythos and Project Glasswing with 286 CVEs as of Friday — and this is only the second of them known to have been exploited in the wild. Rejetto HFS already appears in CISA's Known Exploited Vulnerabilities catalog from 2024, so it is a target with history.
The lesson compounds from both ends. For developers, Math.random() should never touch anything secret — session keys, reset tokens and API secrets belong to crypto.randomBytes or the Web Crypto API, and any endpoint that echoes internal random values to unauthenticated users deserves an immediate audit. For defenders, the patch window is no longer the gap between advisory and exploit. When AI-assisted research makes the write-up and the working attack arrive almost together, deferring the patch to the next cycle is a decision to run internet-facing software unpatched.
Comments (0)
Log in to join the discussion
Log InNo comments yet