
CVE-2026-61500 Active Exploitation Detected Day After Public PoC for Rejetto HFS PRNG Session Forgery
Active exploitation of CVE-2026-61500 began immediately after public PoC release, confirming the persistent window between patch and weaponization. Technical evidence shows targeted reconnaissance from a China Telecom IP rather than broad scanning. The incident underscores how weak PRNG usage in session handling enables rapid RCE once disclosed.
VulnCheck observed the first probes 24 hours after Horizon3.ai and researcher Alejandro Ramos published details of the flaw. The vulnerability stems from Rejetto HFS deriving its Koa session signing key from JavaScript's non-cryptographic Math.random() while exposing PRNG outputs during unauthenticated SRP login responses. An attacker collecting a handful of responses can recover the generator state, sign a valid administrator cookie, and reach the server_code endpoint for arbitrary JavaScript execution and full remote code execution.
The evidence trail shows small-scale reconnaissance rather than mass scanning. A single IP tied to China Telecom tested hosts in Japan and the United States. This follows the July 2026 patch in version 3.2.1, yet public weaponization waited until late September when the PoC surfaced. The pattern mirrors CVE-2024-23692, which saw multiple actors deploy miners and HATVIBE malware after its disclosure.
Anthropic's Mythos model assisted initial discovery at Horizon3.ai, highlighting how AI-assisted code review can surface predictable PRNG usage in authentication paths. The gap between patch availability and PoC release created a three-month window that defenders largely ignored until exploitation telemetry appeared.
Unpatched HFS instances remain exposed to rapid follow-on campaigns. Organizations should prioritize version 3.2.1 deployment and monitor for anomalous login responses that leak PRNG outputs. Similar weak random sources in other file servers warrant immediate audit.
VulnCheck: At least 50 distinct IPs will probe CVE-2026-61500 within 10 days of October 1 2026.
Sources (3)
- [1]VulnCheck Exploitation Report(https://vulncheck.com/blog/rejetto-hfs-oct-2026)
- [2]Horizon3.ai Disclosure(https://horizon3.ai/blog/rejetto-hfs-cve-2026-61500)
- [3]The Hacker News Original(https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html)