Researchers Found Critical Rejetto Server Flaw

A vulnerability in Rejetto HTTP File Server now allows for remote code execution via session cookie manipulation.

Updated on Oct. 3, 2026 in Cybersecurity

Isometric editorial illustration of a dense cluster of modular server racks and cabling, evoking the structure of secure digital infrastructure.
Security researchers identified a critical vulnerability in Rejetto HTTP File Server that allows attackers to bypass authentication and execute remote code. AI Illustration. Upload story photo >

Live Poll

Do you trust artificial intelligence models to help secure critical software systems?

Security researchers discovered a flaw in the Rejetto HTTP File Server that permits authentication bypass and remote code execution. The vulnerability is currently being exploited in the wild.

Why it matters

Attackers are leveraging the weakness to target servers by recovering the pseudo-random number generator seed used for session cookies. Organizations using earlier versions are at risk of unauthorized access and system compromise.

The flaw, tracked as CVE-2026-61500, stems from the use of a non-secure xorshift128+ algorithm that allows for seed recovery. Users must update to version v3.2.1 or later to secure the server.

The players

Anthropic

This AI research company developed the Mythos model used to identify the software vulnerability.

Zach Hanley

He is the security researcher who originally discovered the flaw in the Rejetto file server.

VulnCheck

This cybersecurity firm is responsible for monitoring and reporting on the active exploitation of the vulnerability.

The details

Mythos identified that the application leaked raw outputs through a separate code path, allowing an SMT solver to forge session cookies. Exploitation activity has been detected originating from China, with targets identified in the US and Japan.

Timeline

  1. September 30, 2026: Researcher Zach Hanley uncovered the flaw.

  2. October 1, 2026: CVE-2026-61500 was confirmed to be under exploitation.

  3. October 2, 2026: VulnCheck researchers detected additional exploitation activity.

The Tech Race

This vulnerability highlights the ongoing challenge of securing legacy server architectures against sophisticated AI-assisted analysis. It marks a shift where automated models, such as Project Glasswing, are increasingly used to discover flaws faster than traditional manual audits.

Server administrators must immediately update to version v3.2.1 or later to prevent remote code execution attacks. Failure to patch leaves servers vulnerable to session hijacking and total system compromise by unauthorized actors.

The takeaway

Security teams should prioritize patching software that handles session management using legacy PRNG methods. Relying on outdated or reversible random number generators remains a critical weakness for enterprise file servers.

Further reading

Learn more about the latest threats in Cybersecurity.

Source note: This article includes information reported by TheRegister.

Live Poll

Do you trust artificial intelligence models to help secure critical software systems?