The Pulse
Anthropic’s Mythos-Found HFS Flaw Faces Exploitation a Day Later
Anthropic’s Mythos helped Horizon3 find a Rejetto HTTP File Server flaw that can expose administrator access and enable remote code execution. VulnCheck detected attempted exploitation the next day, with activity targeting vulnerable server

AI.info Team ·
Within a day of Horizon3 publishing details of a Rejetto HTTP File Server flaw found with Anthropic’s Mythos, VulnCheck said it had detected attempts to exploit it against real servers. The first activity appeared Thursday, October 1, after Horizon3 researcher Zach Hanley described the vulnerability on September 30. The incident puts a concrete measure on the short interval between finding a software weakness and seeing someone try to use it.
A predictable key opened the route to admin access
The flaw, tracked as CVE-2026-61500, affects Rejetto HTTP File Server (HFS), open-source software used to host and share files. Horizon3 found that HFS used JavaScript’s Math.random() to generate a value used to sign session cookies. In the V8 engine, that generator’s xorshift128+ output can be reversed; HFS also exposed other outputs from the same generator, giving an attacker clues to reconstruct the signing key.
With the key, an attacker could forge an administrator session cookie. Horizon3 said Mythos connected the weak random-number generator to the separate leak, then used Microsoft’s Z3 constraint solver to recover the generator state. Its proof-of-concept demonstrated a path from unauthenticated access to administrator control and remote code execution, through HFS’s support for custom administrative endpoints that execute JavaScript.
“Mythos negates both of those reasons,” Hanley writes, referring to the expertise and time that researchers said had previously made it difficult to turn cryptographic mistakes into working exploits. Horizon3 says the model identified the linked weaknesses and produced a working proof of concept without follow-up prompting to find the random-number leak.
VulnCheck saw attempts the next day
VulnCheck researcher Patrick Garrity wrote on LinkedIn that his team began detecting exploitation of CVE-2026-61500 on Thursday evening. He said its monitoring systems saw an actor targeting vulnerable hosts in the United States; The Register reported that the first activity came from a China-hosted IP and targeted servers in the US and Japan. Those observations identify the source of network traffic, not the attacker’s identity.
Garrity told The Register that on Friday, October 2, his team saw four more hits from two US-based IP addresses in the same subnet. He said the addresses appeared to be part of a proxy, so their location alone does not establish who was behind the activity. The Register reported that, before this flaw, only one other vulnerability linked to Anthropic’s Mythos and Project Glasswing had been reported exploited in real-world attacks.
HFS users have a version to install
Horizon3’s analysis describes the flaw as a chain rather than a single exposed setting: an attacker needs observable random-number outputs, a way to reconstruct the session-signing key, and a route from administrator access to code execution. That chain matters because the bug turns a weakness in pseudorandom-number generation into a practical authentication bypass.
The Register advises HFS users to update to version 3.2.1 or later, which fixes CVE-2026-61500 along with other security issues. The release is listed on the Rejetto HFS GitHub repository. The reported exploitation attempts began before the technical account had been public for 24 hours.