Attackers target Rejetto HFS flaw CVE-2026-61500 for server access

First reported by The Hacker News at · Updated · 4 sources

A weak pseudo-random number generator can make the session-cookie signing key predictable, allowing attackers to forge sessions, gain administrative access and execute code remotely. VulnCheck has observed exploitation attempts, according to The Hacker News. Security Affairs reports that researchers discovered the vulnerability with help from Anthropic’s Mythos AI model.

  • The vulnerability has a CVSS severity score of 9.3.

Covered by 4 publishers within 12 hours of the first report.

Reporting4

The Hacker News Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE · info@thehackernews.com (The Hacker News)
SecurityWeek Exploitation Hits Rejetto HFS Vulnerability Discovered by AI · Ionut Arghire
Security Affairs Anthropic Mythos Found A Bug in Rejetto HFS. Attackers Are Now Exploiting It. · Pierluigi Paganini
BleepingComputer Rejetto HFS servers now actively scanned for critical RCE flaw · Bill Toulas

Related

Topics Anthropic