Anthropic
Rejetto HFS flaw found by Anthropic's Mythos: what it means
Attackers began exploiting CVE-2026-61500, a critical file-server bug an AI model helped uncover, about a day after a public technical write-up.
The answer
Attackers exploited a critical Rejetto HFS flaw, found with Anthropic's Mythos, about a day after a write-up.
If you run Rejetto HTTP File Server (HFS), a free file-sharing tool, you need to be on version 3.2.1 or later. Attackers have started exploiting a critical flaw in older versions. An AI model from Anthropic helped find it.
What happened
The flaw is tracked as CVE-2026-61500 and scores 9.3 on the CVSS scale, the standard 0–10 severity rating. Researchers at Horizon3.ai, including Zach Hanley, found it using Anthropic's Mythos model, which Anthropic restricts and which is capable of cyber tasks.
The problem lies in how HFS made the values for its session cookies, the small files that keep you logged in. It used JavaScript's Math.random(), a random-number function built on a generator called xorshift128+. That generator can be run in reverse.
According to Horizon3.ai, Mythos used "advanced mathematical reasoning to recognize that Math.random() PRNG outputs could be reversed to reconstruct the secret session-cookie signing key." An attacker who collects login responses can rebuild the generator's internal state and recover the signing key. They can then forge administrator session cookies and run their own code on the server, known as remote code execution. Horizon3.ai said attackers "able to collect other numbers generated by Math.random() could determine other generated numbers and forge the authentication cookies."
The timeline, as reported:
- June 2026: researchers discovered the flaw.
- 13 July: Rejetto released HFS 3.2.1, which fixes it.
- Later: Horizon3 published its technical write-up.
- 2 October: security firm VulnCheck saw exploitation attempts from a China Telecom IP address against decoy systems in Japan and the US, within about 24 hours of the write-up. Four US-based IP addresses followed.
Rejetto's advisory says: "Multiple security vulnerabilities have been found in all previous versions, potentially allowing an attacker to gain administrative access to HFS." The Register called it the second Anthropic-linked vulnerability exploited in the wild, under a headline saying Mythos is "hardcore good at math". The notes also mention that Google's Gemini 4 Argon launched to cyber defenders the same week.
What it means for you
If you use HFS and haven't updated, every version before 3.2.1 is affected. An attacker could take administrator control of your server without a password.
If you don't run HFS, nothing here requires action from you. The report shows an AI model finding a serious bug, and attackers acting within about a day of the details becoming public.
How to try it
You can't try the exploit, and you shouldn't. The step that matters is the fix: upgrade Rejetto HFS to version 3.2.1 or later.
More detail is in SecurityWeek's report and a DEV Community write-up of the timeline.
Sources
- Exploitation Hits Rejetto HFS Vulnerability Discovered by AI — SecurityWeek, 5 October 2026
- Rejetto HFS CVE-2026-61500 exploited a day after write-up — DEV Community, 4 October 2026