Researchers Uncovered Critical Rejetto Server Vulnerability

The newly identified flaw allows for remote code execution, with active exploitation of the server now underway.

Updated on Oct. 3, 2026 in Cybersecurity

Isometric editorial illustration of a modular industrial server rack enclosure rendered in slate blue, teal, and cream, symbolizing cybersecurity infrastructure.
Security researchers identified a critical vulnerability in Rejetto's HTTP File Server, allowing for remote code execution by exploiting predictable session cookie generation. AI Illustration. Upload story photo >

Live Poll

Do you trust artificial intelligence models to help secure critical software systems?

Security researchers have identified CVE-2026-61500, a critical vulnerability in the Rejetto HTTP File Server that permits authentication bypass and remote code execution. The flaw is currently being exploited in the wild, targeting servers across multiple regions.

Why it matters

This discovery highlights the efficacy of AI-driven security analysis in finding complex, non-obvious logic flaws in widely used server infrastructure. Automated identification of such weaknesses is increasingly vital as attackers utilize similar tools to scan and exploit exposed systems.

The vulnerability stems from the use of a non-secure pseudo random number generator (PRNG) for session cookies, where the xorshift128+ algorithm used by V8 was found to be reversible. By leaking raw Math.random outputs, the system allowed for the recovery of the PRNG seed via an SMT solver to forge session cookies.

The players

Anthropic

An AI research lab focused on developing safe large-scale models and specialized tools for vulnerability discovery.

Zach Hanley

The security researcher who identified the specific session cookie weakness in the Rejetto HTTP File Server.

VulnCheck

A cybersecurity firm that tracks and analyzes vulnerabilities and emerging exploit activity in the wild.

Horizon3

A security firm specializing in automated penetration testing and active cyber defense.

The details

Mythos, an AI model within Anthropic's Project Glasswing, identified that the Rejetto HTTP File Server leaks raw outputs from the Math.random function through a secondary code path. An SMT solver—a specialized software tool for solving logical constraints—used this leaked data to derive the PRNG seed. With the seed recovered, an attacker can generate predictable session cookies, bypass authentication, and execute arbitrary code on the host machine.

Timeline

  1. April 2026: Anthropic announced the Project Glasswing program.

  2. July 2026: Horizon3 joined the Project Glasswing program.

  3. September 30, 2026: Researcher Zach Hanley uncovered the flaw.

  4. October 1, 2026: CVE-2026-61500 was under exploitation.

  5. October 2, 2026: VulnCheck researchers detected exploitation activity.

The Tech Race

This vulnerability discovery reflects the broader shift toward using AI agents to perform complex, automated vulnerability research. It follows the momentum of Project Glasswing, which is currently scaling its capacity to identify security flaws across critical infrastructure.

System administrators must immediately update Rejetto HTTP File Server to version 3.2.1 or later to secure their environments. Those failing to patch remain vulnerable to remote code execution and session hijacking by any attacker capable of reversing the PRNG seed.

The takeaway

The move toward AI-automated vulnerability research has significantly shortened the time between software flaw discovery and active exploitation. Administrators should prioritize updating to v3.2.1 to neutralize the current threat posed by CVE-2026-61500.

Further reading

For more updates on emerging software vulnerabilities, visit the Cybersecurity section.

Live Poll

Do you trust artificial intelligence models to help secure critical software systems?