Researchers Uncovered Critical Rejetto Server Vulnerability
The newly identified flaw allows for remote code execution, with active exploitation of the server now underway.
Updated on Oct. 3, 2026 in Cybersecurity

Live Poll
Do you trust artificial intelligence models to help secure critical software systems?
Security researchers have identified CVE-2026-61500, a critical vulnerability in the Rejetto HTTP File Server that permits authentication bypass and remote code execution. The flaw is currently being exploited in the wild, targeting servers across multiple regions.
Why it matters
This discovery highlights the efficacy of AI-driven security analysis in finding complex, non-obvious logic flaws in widely used server infrastructure. Automated identification of such weaknesses is increasingly vital as attackers utilize similar tools to scan and exploit exposed systems.
The vulnerability stems from the use of a non-secure pseudo random number generator (PRNG) for session cookies, where the xorshift128+ algorithm used by V8 was found to be reversible. By leaking raw Math.random outputs, the system allowed for the recovery of the PRNG seed via an SMT solver to forge session cookies.
The players
Anthropic
An AI research lab focused on developing safe large-scale models and specialized tools for vulnerability discovery.
Zach Hanley
The security researcher who identified the specific session cookie weakness in the Rejetto HTTP File Server.
VulnCheck
A cybersecurity firm that tracks and analyzes vulnerabilities and emerging exploit activity in the wild.
Horizon3
A security firm specializing in automated penetration testing and active cyber defense.
The details
Mythos, an AI model within Anthropic's Project Glasswing, identified that the Rejetto HTTP File Server leaks raw outputs from the Math.random function through a secondary code path. An SMT solver—a specialized software tool for solving logical constraints—used this leaked data to derive the PRNG seed. With the seed recovered, an attacker can generate predictable session cookies, bypass authentication, and execute arbitrary code on the host machine.
Timeline
April 2026: Anthropic announced the Project Glasswing program.
July 2026: Horizon3 joined the Project Glasswing program.
September 30, 2026: Researcher Zach Hanley uncovered the flaw.
October 1, 2026: CVE-2026-61500 was under exploitation.
October 2, 2026: VulnCheck researchers detected exploitation activity.
The Tech Race
This vulnerability discovery reflects the broader shift toward using AI agents to perform complex, automated vulnerability research. It follows the momentum of Project Glasswing, which is currently scaling its capacity to identify security flaws across critical infrastructure.
System administrators must immediately update Rejetto HTTP File Server to version 3.2.1 or later to secure their environments. Those failing to patch remain vulnerable to remote code execution and session hijacking by any attacker capable of reversing the PRNG seed.
The takeaway
The move toward AI-automated vulnerability research has significantly shortened the time between software flaw discovery and active exploitation. Administrators should prioritize updating to v3.2.1 to neutralize the current threat posed by CVE-2026-61500.
Further reading
For more updates on emerging software vulnerabilities, visit the Cybersecurity section.
Live Poll
Do you trust artificial intelligence models to help secure critical software systems?






