Skip to main content
WireRead
Back to all news

Anthropic

Attackers exploit Rejetto HFS flaw found by Anthropic's Mythos

Exploitation of CVE-2026-61500, a critical bug in Rejetto HTTP File Server, began about a day after a public technical write-up.

By , Editor-in-Chief · WireReadVerified October 2026

The answer

Attackers exploited critical Rejetto HFS flaw CVE-2026-61500, found by Mythos, about a day after a write-up.

Attackers began exploiting a critical flaw in Rejetto HTTP File Server (HFS) within about a day of a public technical write-up, according to SecurityWeek. Researchers found the bug using Anthropic's Mythos model.

SecurityWeek said the flaw, CVE-2026-61500, has a CVSS score of 9.3. An attacker can use it to forge administrator session cookies and gain remote code execution.

HFS used JavaScript's Math.random() function to make session-cookie values. That function uses the xorshift128+ generator, which can be reversed. An attacker who collects login responses can reconstruct the generator's state and recover the signing key.

Horizon3.ai researcher Zach Hanley found the flaw using Mythos in June 2026. Horizon3.ai said attackers "able to collect other numbers generated by Math.random() could determine other generated numbers and forge the authentication cookies." The report said Mythos used "advanced mathematical reasoning to recognise that Math.random() PRNG outputs could be reversed to reconstruct the secret session-cookie signing key."

Rejetto released HFS 3.2.1, which patches the flaw, on 13 July. Horizon3 later published its technical write-up. Rejetto's advisory said: "Multiple security vulnerabilities have been found in all previous versions, potentially allowing an attacker to gain administrative access to HFS."

VulnCheck saw the first exploitation attempts on 2 October, according to a DEV Community report. The attempts came from a China Telecom IP address and targeted canary systems in Japan and the US. Four US-based IP addresses followed.

The Register called it the second Anthropic-linked vulnerability exploited in the wild. Its headline said Mythos is "hardcore good at math". Mythos is Anthropic's restricted model with cyber capabilities. Google's Gemini 4 Argon launched to cyber defenders the same week.

Rejetto said administrators should upgrade to HFS 3.2.1 or later.

Sources

← All news