How Can AI Uncover Critical Flaws in Rejetto File Servers?

How Can AI Uncover Critical Flaws in Rejetto File Servers?

Malik Haidar stands at the intersection of corporate resilience and deep-technical threat intelligence. With a career forged in the high-stakes environments of multinational corporations, he has managed the complex balance between business operations and high-level security analytics. His experience makes him a leading voice on how modern organizations must adapt to vulnerabilities that are no longer just discovered by human eyes, but by the relentless logic of artificial intelligence. Today, he shares his perspective on the critical CVE-2026-61500 flaw within the Rejetto HTTP File Server, a case study in how small coding choices can lead to a total collapse of authentication and remote code execution.

Many systems rely on non-cryptographic generators like xorshift128+ for session management; what makes this specifically lethal in the context of the Rejetto HFS vulnerability?

The core of the danger lies in the predictable nature of the xorshift128+ algorithm, which was never intended to support a high-stakes security perimeter. In Rejetto HFS, the Math.random() function leaked its outputs to unauthenticated clients, creating a trail of digital breadcrumbs that an attacker could follow to reconstruct the entire state of the generator. With a CVSS score of 9.3, this isn’t just a minor leak; it is a fundamental failure that allows an adversary to recover the exact signing key used for session cookies. It’s a chilling reality for any administrator to realize that simply collecting a small set of login responses is enough for a stranger to forge a master key. Once that key is in hand, the attacker effectively becomes the administrator, gaining full access to the server.

The discovery of this flaw involved Anthropic’s Mythos AI model; how is the integration of advanced mathematical reasoning in AI changing the way we find these reversible logic flaws?

We are entering an era where AI can see through layers of mathematical complexity that even seasoned researchers might overlook during a manual code audit. In this instance, the Mythos AI model was able to apply advanced reasoning to recognize that the outputs of the pseudo-random number generator could be reversed to reveal the secret signing key. This represents a massive shift in vulnerability research, moving away from simple brute-force fuzzing toward deep, symbolic logic analysis. It’s a double-edged sword; while researchers used this technology to alert Rejetto in June, it also serves as a warning that attackers are gaining the same capabilities. The speed at which an AI can perform these calculations means that any logic relying on “security through complexity” is no longer a viable defense against a modern threat actor.

We have seen reports of exploitation attempts originating from a China Telecom IP hitting canaries in the US and Japan; what does this indicate about how quickly threat actors are operationalizing these findings?

The shift to active exploitation on October 2 signals that the grace period for patching has officially ended, and the “wild west” phase of the exploit lifecycle has begun. These reconnaissance efforts, which were detected hitting canary systems across two major continents, show that sophisticated actors are already scanning for the low-hanging fruit of unpatched servers. It creates a palpable sense of urgency because we aren’t just talking about a theoretical bypass; this is a path to remote code execution via the server’s own configuration features. Seeing traffic from a China Telecom IP suggests that global threat groups are now operationalizing the technical reports released by firms like Horizon3. For organizations that haven’t yet moved to version 3.2.1, the window of opportunity to secure their data is closing incredibly fast as these scans turn into active breaches.

What is your forecast for the evolution of session-based attacks as AI becomes more prevalent in both defense and offense?

I anticipate a significant surge in “logic-based” breaches where attackers use AI to exploit the subtle, non-obvious flaws in how data is generated, signed, and validated across the web. We will likely see a decline in the effectiveness of standard non-cryptographic functions, as AI-driven tools will be able to crack them in near real-time, much like what happened with Rejetto HFS. Organizations will be forced to migrate toward strictly cryptographic, hardware-backed entropy sources to ensure that their “random” values are truly unpredictable. The human-only audit is rapidly becoming a relic of the past; if your security architecture isn’t being validated by the same level of AI reasoning that adversaries use, you are essentially leaving the vault door unlocked. In the coming months, I expect we will see a fundamental transformation in how web frameworks handle session security, moving toward more resilient, AI-proof protocols.

subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address
subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address