
Anthropic's Mythos found a critical Rejetto HFS flaw that was exploited within a day
Horizon3 researcher Zach Hanley used Anthropic's bug-hunting model Mythos to find CVE-2026-61500, a critical authentication bypass in Rejetto HFS. Exploitation attempts began the next day from a China-hosted IP; the fix is in HFS v3.2.1.
Exploitation attempts against a critical vulnerability in Rejetto HTTP File Server (HFS) began within a day of its disclosure. Tracked as CVE-2026-61500, the bug is an authentication bypass that can give an attacker full admin access and remote code execution on the server; the first activity came from an IP address in China targeting vulnerable hosts in the United States and Japan.
From disclosure to attacks in one day
The flaw was found by Zach Hanley, a researcher at AI pen-testing company Horizon3, using Anthropic's bug-hunting model Mythos. Hanley published the finding on Wednesday, along with a video of the exploitation steps. HFS is an open source web file server; the fix is in v3.2.1 or later.
By Thursday evening, VulnCheck researcher Patrick Garrity reported that attacks had already started. “Our canaries detected an actor in China targeting real vulnerable hosts in the US,” he wrote on LinkedIn. On Friday, Garrity told The Register that four more hits came from two IP addresses in the same US subnet, which appeared to be a proxy.
Reversible randomness
According to Hanley's write-up, the weakness starts with how HFS authenticates users. The server generates a random value with Math.random() and passes it to Koa, the Node.js framework under HFS, which signs session cookies with that value via keygrip. An attacker who can derive the signing key can forge valid session cookies.
The problem is that V8's Math.random() is not a secure generator: it uses the xorshift128+ algorithm, whose output is fully reversible. Mythos noticed that the application leaked raw Math.random() outputs through a separate code path, chained the two facts together, and determined that the leak produces exactly the observations needed to recover the generator's state. The model proposed using Z3, Microsoft's publicly available SMT solver, then built a working exploit that executed an arbitrary command. Horizon3 says its researchers cannot recall an SMT solver being used this way against a crypto flaw in a real app before.
Why it matters
CVE-2026-61500 is only the second Anthropic-linked vulnerability known to have been exploited in the wild. Garrity's tracker counted 286 CVEs attributed to Mythos and to Project Glasswing, the program that gives select partners access to the model, as of Friday, and until Thursday only one of those bugs had been exploited in real-world attacks. Anthropic claims Mythos is too powerful to release to the general public.
Horizon3, which joined Project Glasswing in July, says the model's ability to reason about mathematics and cryptography changes the kinds of bugs attackers are likely to weaponize at scale.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.