Critical Rejetto HFS Flaw Enables Remote Code Execution, Attackers Already Exploiting It
A severe vulnerability in the Rejetto HTTP File Server (HFS) has been confirmed as actively exploited, allowing unauthenticated attackers to bypass login controls and execute arbitrary code on affected systems.
The flaw, catalogued as CVE-2026-61500, carries a CVSS rating of 9.3, indicating a high potential for damage. Researchers determined that the bug permits authentication bypass followed by remote code execution, effectively giving threat actors full control over the compromised server.
The vulnerability was uncovered through an AI‑assisted research project that leveraged Anthropic's Mythos model to automate parts of the code‑review process. By scanning the HFS source for unsafe patterns, the AI highlighted the problematic routine, which was then validated by human analysts and reported to the vendor.
Rejetto HFS is widely used by small businesses and hobbyists to share files over a web interface because of its lightweight footprint. The newly discovered weakness puts any publicly reachable instance at risk, especially those that have not been updated in years. Successful exploitation could lead to data theft, ransomware deployment, or the server being conscripted into larger botnets.
Following the disclosure, the developer issued an emergency patch that addresses the authentication bypass and hardens the execution path. Security teams are advised to apply the update immediately, restrict network access to trusted hosts, and monitor logs for unusual activity that might indicate a breach.
The episode underscores the growing role of generative AI in vulnerability discovery, while also highlighting the need for rapid patch deployment. As AI tools become more capable, both defenders and attackers are likely to accelerate the pace at which critical bugs surface and are weaponized.
Comments (0)
Be the first to comment.
Join the discussion