Skip to main content
CybersecurityVulnerability Management

Mythos Exposes New Vulnerability in Rejetto HTTP File Server

Server room with rows of computer equipment and a prominent server in the foreground.

“We started detecting exploitation of CVE-2026-61500 in Rejetto HFS this evening,” VulnCheck security researcher Patrick Garrity posted on LinkedIn on Thursday, adding that Hanley and team reported the bug to VulnCheck for CVE assignment.

CVE-2026-61500: a critical authentication bypass in Rejetto HFS

Researcher Zach Hanley of Horizon3 used Anthropic’s bug-hunting model Mythos to uncover a critical authentication-bypass vulnerability in Rejetto HTTP File Server (HFS) now tracked as CVE-2026-61500. The flaw can lead to full administrator access and remote code execution. Hanley published a write-up and a video demonstrating the steps to exploit HFS and remotely execute code on the server. Rejetto HFS appears in the U.S. Cybersecurity and Infrastructure Security Agency’s catalog of Known Exploited Vulnerabilities from 2024.

How Mythos linked an insecure PRNG, a leak, and an SMT solver

Hanley’s analysis, using Mythos, identified a technical chain that made attack feasible. HFS generated a random value using Math.random() and passed it into Koa, the Node.js framework. Koa uses keygrip to sign all session cookies with that random value, meaning that if an attacker can derive the session signing key they can forge valid session cookies and bypass authentication.

Mythos recognised two connected problems: V8’s Math.random() relied on an xorshift128+ implementation whose outputs are reversible, and the HFS application leaked raw Math.random() outputs via a separate code path. The model’s analysis claimed that the Microsoft-developed SMT solver Z3 could be used to recover the PRNG seed from the leaked outputs. Hanley wrote that Horizon3’s researchers could not recall seeing an SMT solver used this way to attack a cryptographic flaw in a real application and bypass authentication.

Timeline and observed exploitation: from disclosure to real-world hits

Horizon3 reported the bug to VulnCheck and the CVE was assigned. Hanley said Horizon3 has used Mythos in its vulnerability research since joining Anthropic’s Project Glasswing in July, and that the company has discovered “many critical vulnerabilities” with the model.

By Thursday night, VulnCheck’s canaries detected exploitation activity. Garrity told The Register the initial activity came from one IP address in China and targeted vulnerable hosts in the United States and Japan. By Friday, Garrity reported seeing four hits originating from two U.S. IP addresses—173.239.211[.]248 and 173.239.211[.]249—which are in the same subnet and “appear to be coming from a proxy,” he said.

Mythos, Project Glasswing, and the scale of findings

Garrity has tracked CVEs attributed to Mythos and Project Glasswing since the program’s announcement in April. According to his tracker, Mythos and Project Glasswing have uncovered 286 CVEs as of Friday. Up until Thursday, Garrity said, only one of those bugs had been exploited in real-world attacks; CVE-2026-61500 represents the second Anthropic-linked vulnerability known to have been exploited in the wild.

Anthropic has described Mythos as too powerful for general release and runs Project Glasswing to provide select partners controlled access to the model. Horizon3 is one of those partners and reported the HFS bug, Hanley wrote.

What this means for Rejetto HFS operators, Horizon3 and VulnCheck, and network defenders

  • Rejetto HFS operators: update to v3.2.1 or later, which the source says fixes CVE-2026-61500 and other security flaws.
  • Horizon3 and VulnCheck (research and tracking teams): continue to report, track, and publish technical details; Garrity’s canaries found exploitation quickly after disclosure and his tracker aggregates Mythos-attributed CVEs.
  • Network defenders and incident responders: watch for exploitation attempts originating from the IP addresses named (initially a China-based IP and later 173.239.211[.]248 and 173.239.211[.]249 in the same subnet) and for attempts to present forged session cookies consistent with an authentication-bypass.

The technical arc of CVE-2026-61500 — an insecure PRNG, an application-level leak of raw PRNG outputs, and the use of an SMT solver to recover seed state — is notable because, Hanley wrote, Mythos “didn’t just flag the insecure PRNG in isolation” but chained together those facts to demonstrate a practical exploit. That chaining, the quick move from publication to observed exploitation, and the tally of 286 Mythos-attributed CVEs all raise a pointed, immediate question grounded in the record: how many of those findings will be weaponized rapidly once disclosed?

Source: The Register — Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows