Security & Privacy | 3 min read

CVE-2026-61500: Anthropic Mythos-Found Flaw in Rejetto HFS Under Active Attack Within 24 Hours

A critical authentication-bypass flaw in Rejetto HTTP File Server, discovered using Anthropic's Mythos AI model, came under active China-linked exploitation less than 24 hours after public disclosure.

Hector Herrera
Hector Herrera
A cybersecurity operations center featuring Server, server, related to CVE-2026-61500: an AI safety company Mythos-Found Flaw in Re
Why this matters A critical authentication-bypass flaw in Rejetto HTTP File Server, discovered using Anthropic's Mythos AI model, came under active China-linked exploitation less than 24 hours after public disclosure.

A critical authentication-bypass flaw in Rejetto HTTP File Server came under active exploitation on October 4 — less than 24 hours after Wednesday's public disclosure. If you run HFS, update to version 3.2.1 immediately. The flaw was found not by a human researcher working alone, but by security researcher Zach Hanley using Anthropic's Mythos AI model, marking one of the first confirmed cases of an AI-assisted CVE going from discovery to mass exploitation in under a day.

The Flaw

Rejetto HFS (HTTP File Server) is a lightweight, free file-sharing tool widely used on Windows by small businesses, home labs, and individual users who want a simple way to serve files over a local network or the internet. CVE-2026-61500 is an authentication bypass — meaning an attacker can gain access to the server without a valid username or password.

The mechanism is subtle but reproducible. HFS derives its session-cookie encryption key from JavaScript's Math.random() function. That function is not cryptographically secure — its output is deterministic and reversible if you know the seed. A separate code path in HFS leaks enough Math.random() output to reconstruct the seed. Combined, these two flaws allow an attacker to forge a valid session cookie and authenticate as any user, including the administrator.

Hanley used Anthropic's Mythos — a model Anthropic has positioned as specialized for mathematical reasoning and vulnerability research — to identify the connection between the two code paths. According to The Register's reporting, Mythos flagged the Math.random() seed-recovery angle as the critical link that turned a theoretical information-leak into a practical authentication bypass.

Active Exploitation in Under 24 Hours

The CVE was disclosed publicly on October 3. By October 4, VulnCheck's canary infrastructure — honeypot servers instrumented to detect attacks — had logged active exploitation attempts. The attacking IP addresses were traced to China-based infrastructure, with U.S. and Japanese HFS deployments as the primary targets.

The speed of exploitation is notable but not unprecedented for high-value, low-complexity flaws. An authentication bypass that requires no prior credentials and runs against a widely deployed tool is exactly the kind of vulnerability that automated exploit frameworks pick up immediately after disclosure.

What This Means for Defenders

Short term: Patch now. Rejetto has released HFS 3.2.1, which replaces the Math.random()-based key derivation with a cryptographically secure pseudorandom number generator (CSPRNG). The update is available on the Rejetto GitHub repository.

If you cannot patch immediately, the interim mitigations are:

  • Place HFS behind a VPN or IP allowlist so it is not exposed directly to the internet
  • Rotate all existing session tokens (restart the HFS service)
  • Monitor logs for unexpected authentication events

Longer term: CVE-2026-61500 is an early data point in a larger question: what happens to the vulnerability disclosure ecosystem when AI models can find flaws faster than human researchers? The traditional 90-day responsible disclosure window assumes a race between a researcher notifying a vendor and a separate attacker independently discovering the same flaw. If AI models compress discovery timelines on both sides, that 90-day window may need to shrink.

The Mythos Angle

Anthropic's Mythos model has not been publicly released. It has been described by Anthropic researchers as a specialized system optimized for mathematical reasoning and structured vulnerability analysis — distinct from Claude's general-purpose design. Hanley's use of Mythos to find CVE-2026-61500 is one of the first public demonstrations of the model's capabilities in a real-world offensive security context.

The finding raises a straightforward question that the security industry has not yet answered cleanly: when an AI model finds a vulnerability, who bears disclosure responsibility — the researcher who ran the query, the lab that built the model, or both?

What to Watch

Whether Anthropic clarifies its policy on Mythos-assisted vulnerability disclosure, and whether CISA (the U.S. Cybersecurity and Infrastructure Security Agency) adds CVE-2026-61500 to its Known Exploited Vulnerabilities catalog — which would trigger mandatory patching timelines for federal agencies. Given the confirmed active exploitation, that listing is likely.

Key Takeaways

  • ✓ If you run HFS, update to version 3.2.1 immediately.
  • ✓ authentication bypass
  • ✓ not cryptographically secure

Did this help you understand AI better?

Your feedback helps us write more useful content.

Hector Herrera

Written by

Hector Herrera

Hector Herrera is an AI systems architect in Houston and founder of Hex AI Systems. He designs and runs AI systems in production and writes daily about how AI is reshaping business, government and everyday life. 20+ years building for the web. Houston, TX.

More from Hector →

Get tomorrow's AI briefing

Join readers who start their day with NexChron. Free, daily, no spam.

More from NexChron