• 4 min read
Mythos turns vulnerability research into an exploit-response race
A Mythos-discovered HFS authentication bypass was reportedly exploited within a day. Patch v3.2.1 or later; the model found a reversible PRNG chain, not merely a weak API call.

Image: The Register
A critical authentication-bypass vulnerability in Rejetto HTTP File Server (HFS) was reportedly exploited in the wild within a day of disclosure. Anthropic’s restricted Mythos model identified the bug, and the technical details needed to validate it also shorten the time attackers have to weaponize it.
The flaw, CVE-2026-61500, can give a remote attacker full administrator access and enable remote code execution. Rejetto’s fix is HFS v3.2.1 or later. Organizations running internet-reachable HFS instances should treat the upgrade as urgent, particularly because exploitation telemetry has already targeted systems in the United States and Japan.
The reported initial traffic came from an IP address in China. Follow-on detections involved four hits from two U.S. IP addresses, 173.239.211[.]248 and 173.239.211[.]249, which were in the same subnet and appeared to be proxy traffic. That does not establish the operator’s physical location; it establishes the origin points observed by the canary systems. Proxy infrastructure makes IP-based attribution a weak basis for stronger conclusions.

Recommended reading
Apple’s AI-agent fix is consent, not least privilege
Sergey Kuznetsov • • 8 min read
The authentication chain Mythos identified
The vulnerability was not simply that HFS used JavaScript’s Math.random(). The finding was the chain between a predictable random-number source and data leakage elsewhere in the application.
HFS generated a value with Math.random() and passed it through Koa, the Node.js framework underpinning the server. Koa uses keygrip to sign session cookies with that value. If an attacker can reconstruct the signing key, they can forge a cookie the server accepts as valid and bypass authentication.
That should be infeasible if the random generator is cryptographically secure and its state remains private. But the reported runtime’s V8 implementation used the reversible xorshift128+ algorithm for Math.random(), rather than a secure pseudorandom number generator. HFS also exposed raw Math.random() values through a separate path. Mythos connected the two conditions and concluded that the disclosed values supplied sufficient observations to recover internal generator state.
The model proposed using Z3, Microsoft’s satisfiability-modulo-theories solver, to solve the state-recovery constraints. Horizon3's account says its researchers could not recall seeing an SMT solver used to turn an application-level random-number leak into an authentication bypass in a real product. A scanner can flag a non-cryptographic PRNG, but the practical work is establishing that its outputs leak, the leak is sufficient, and a recovered state can be converted into a useful credential.
The attack path is compact: observe leaked outputs, solve for the PRNG state, derive the cookie-signing material, forge an authenticated session, then use administrator access to execute code. Public exploitation instructions and a video demonstration make the immediate patching requirement more serious.
HFS already had an exploitation record
HFS is not new to CISA’s Known Exploited Vulnerabilities catalog. The catalog currently shows two older HFS flaws, including one marked as used in ransomware campaigns. It does not show CVE-2026-61500 in the supplied catalog record, so the catalog cannot yet be read as confirmation that CISA has added this newest flaw.
| CVE | CISA date added | Vulnerability described by CISA | Required action |
|---|---|---|---|
| CVE-2024-23692 | July 9, 2024 | Template-engine special-element neutralization failure enabling unauthenticated command execution | Apply vendor mitigations or discontinue use if none are available |
| CVE-2014-6287 | March 25, 2022 | findMacroMarker remote code execution flaw | Apply vendor updates |
The older entries affect the priority calculation. HFS has an established history of remotely exploitable issues and a documented ransomware association for CVE-2024-23692. A newly exploited flaw that ends in admin-level code execution belongs at the front of the remediation queue, regardless of whether an organization considers the exposed service important enough to monitor closely.
Glasswing’s output is becoming attacker-relevant
Anthropic has limited Mythos access through Project Glasswing, rather than offering the vulnerability-research model broadly. Horizon3 joined the program in July 2026 and says it has since found many critical vulnerabilities with the model. A tracker maintained by VulnCheck researcher Patrick Garrity counted 286 CVEs attributed to Mythos and Project Glasswing as of October 3, 2026; CVE-2026-61500 was reportedly only the second one known to have been exploited in real attacks.
That count needs a careful reading. It is not a benchmark of how many vulnerabilities Mythos independently found, nor does it show how many were critical, patched, or practically exploitable. It does show that a restricted research program is generating enough assigned CVEs that vulnerability disclosure and patch deployment matter as much as model access controls.
Anthropic’s earlier security work has focused partly on enterprise defenses. In August 2026, it introduced Claude Enterprise inference hooks intended to inspect and block prompts and tool responses before Claude processes them. In September 2026, its Fable 5.1 and restricted Mythos 5.1 release added enterprise privacy controls. Those measures address what customer inputs and tool calls can reach a model. They do not protect an HFS administrator who has not yet deployed a vendor patch after vulnerability details enter the public domain.
A model can reduce the labor required to recognize that several ordinary implementation choices form an exploit chain. It cannot create maintenance windows, identify every exposed deployment, or force an operator to upgrade. The limiting factor is how quickly defenders can move from a CVE notice to v3.2.1 on their actual servers.
Frequently asked questions
How do I fix CVE-2026-61500 in Rejetto HFS?+
Upgrade Rejetto HTTP File Server to v3.2.1 or later. The reported flaw can bypass authentication, yield administrator access, and enable remote code execution.
Is CVE-2026-61500 in CISA’s KEV catalog?+
The supplied CISA catalog record lists two older Rejetto HFS vulnerabilities, CVE-2024-23692 and CVE-2014-6287. It does not list CVE-2026-61500.
How did the HFS authentication bypass work?+
The reported chain combined reversible Math.random() output, leakage of raw outputs through another HFS path, and session-cookie signing through Koa/keygrip. Z3 was proposed to recover the PRNG state and enable cookie forgery.
Editor-in-Chief
Sergey Kuznetsov is Head of Product at iXBT.com, one of the largest Russian-language technology media outlets, and the founder of itzine.ru. He has spent over a decade building and running tech newsrooms. At for(geeks) he sets editorial standards and reviews what ships.


