Summary
A single misstep in code validation has left OneDev’s DevOps platform exposed, letting even low-privileged insiders seize root control and potentially compromise entire servers. Cyware spotlights how Vulnetic’s AI-driven probe traced the flaw to Groovy script compilation, with a patch now available but no exploitation reported so far.
A newly disclosed zero-day in KVM has the virtualization community on edge, as researchers warn of a VM escape that could let attackers leap from guest to host and seize root access. The Vercel Sandbox bounty post has already drawn 38,600 views, but patch status remains unresolved at publication.
Attackers are actively bypassing authentication in Rejetto HFS, forging session cookies to hijack admin rights and run code remotely. The flaw, tracked as CVE-2026-61500, has already been exploited in the US and Japan, with researchers using Anthropic’s Mythos model to pinpoint the PRNG weakness. HFS 3.2.1 fixes the issue.
Top Vulnerabilities Reported in Last 24 hours
OneDev bug lets insiders reach root
A newly reported remote code execution flaw in the OneDev DevOps platform lets a low-privileged, authenticated user run code as root, opening the door to server takeover and data theft. Vulnetic says the issue comes from a dangerous order-of-operations mistake: certain endpoints compile attacker-influenced Groovy during validation, before authorization meaningfully blocks the request, so the exploit can succeed even when the server ultimately returns an error. The finding came from Vulnetic’s AI tool Sable, which enumerated @Code usage, CodeValidator mode, and GroovyUtils.compile calls, and traced execution into historical Groovy components such as ASTTest and GroovyClassLoader.parseClass(). No active exploitation has been reported in the provided source. A patch is available from OneDev (per the report).
KVM zero-day raises VM escape fears
A confirmed zero-day in KVM (Kernel-based Virtual Machine) could allow a full VM escape, potentially letting an attacker jump from a guest virtual machine to root access on the host. In practical terms, that kind of breakout can turn a single compromised workload into control over the underlying server running multiple systems. No active exploitation has been reported in the provided source. The discovery was shared publicly by Guillermo Rauch (Vercel CEO) as part of the Vercel Sandbox bounty program, with significant contribution credited to researcher Paulos Yibelo. The post drew 38.6K views and 47 replies, reflecting heightened community concern while patch status remains unresolved in the source.
Hackers exploit Rejetto HFS login bypass
Attackers are actively exploiting an authentication-bypass flaw in Rejetto HTTP File Server (HFS) that can lead to remote code execution and full administrative control (CVE-2026-61500). The weakness stems from an insecure pseudo-random number generator in HFS’s authentication flow: researchers report the application leaks Math.random() outputs, which can be used to reconstruct the PRNG state and forge valid session cookies. TheRegister reports that attackers have already targeted vulnerable servers, with observed activity involving compromised devices used as proxies, and targeting noted in the US and Japan. The flaw was discovered using Anthropic’s Mythos model, which identified that a Z3 SMT solver could be used to recover the PRNG seed and generate authenticated sessions. A fix is available in HFS 3.2.1 or later.
Frequently Asked Questions
What is OneDev? A newly reported remote code execution flaw in the OneDev DevOps platform lets a low-privileged, authenticated user run code as root, opening the door to server takeover and data theft. Vulnetic says the issue comes from a dangerous order-of-operations mistake: certain endpoints compile attacker-influenced Groovy during validation, before authorization meaningfully blocks the request, so the exploit can succeed even when the server ultimately returns an error.
What is KVM? A confirmed zero-day in KVM (Kernel-based Virtual Machine) could allow a full VM escape, potentially letting an attacker jump from a guest virtual machine to root access on the host. In practical terms, that kind of breakout can turn a single compromised workload into control over the underlying server running multiple systems.
What is CVE-2026-61500? Attackers are actively exploiting an authentication-bypass flaw in Rejetto HTTP File Server (HFS) that can lead to remote code execution and full administrative control (CVE-2026-61500). The weakness stems from an insecure pseudo-random number generator in HFS’s authentication flow: researchers report the application leaks Math.random() outputs, which can be used to reconstruct the PRNG state and forge valid session cookies.


