Skip to content
cve — cve-2026-61500

grep -rl "CVE-2026-61500" ./articles

CVE-2026-61500

Rejetto HFS signed its session cookies with a key from JavaScript's Math.random, and handed out numbers from the same generator to anyone who started a login. Either alone is survivable. Together they let a stranger forge an admin session and run code. Horizon3 found it with Anthropic's Mythos, published a proof of concept, and scanning began within days.

1 article — 2026-10-06

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

../cve — every identifier we have covered